πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1192 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5657ffe2-7d04-4834-bcec-ab6afaeda7df MEDIUM 5.3 The Ovic Product Bundle plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… wordfence
5652224e-348f-4e71-b2b1-0bca9846f949
< 1.2.3
MEDIUM 5.3 The Rara Academic theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
563f7d55-1df0-4bdc-b9be-5e564241bcf6 MEDIUM 5.3 The HREFLANG Tags Lite plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on t… wordfence
563d01c1-dead-4d1a-9f4a-39351b8e94cb
< 10.1.77
MEDIUM 5.3 The WP Cost Estimation & Payment Forms Builder plugin for WordPress is vulnerable to unauthorized access due to a missin… wordfence
56382dd8-7f02-4544-a530-31c012407ab7
< 4.25
MEDIUM 5.3 The Grand Flagallery plugin before 4.25 for WordPress allows remote attackers to obtain the installation path via a requ… wordfence
561ec1b2-ee26-4e0c-b437-d70b04be5b4c
< 5.4
MEDIUM 5.3 The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, … wordfence
561c6906-1db0-49de-b291-b0eef4a62b98 MEDIUM 5.3 The Rich Text Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
5618db77-fe74-4982-92b3-cec554640bde
< 5.0.26
MEDIUM 5.3 The Hide My WP Ghost plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 5.0.25. This… wordfence
560cd314-e442-4284-948f-e654445e0765
< 1.7.17
MEDIUM 5.3 The Shared Files plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… wordfence
56036bb2-3af3-4f69-ab79-78c5bb266231
< 5.2
MEDIUM 5.3 The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not valid… wordfence
55f866b3-2d33-4d92-ab4f-0cc0bee75b9b
< 5.4.31
MEDIUM 5.3 The Woffice Core plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu… wordfence
55db5fce-0deb-4d1b-a103-b312fb83fac9
< 2.0.0
MEDIUM 5.3 The Simple Like Page plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
55a103a7-c5d8-4b52-8291-e4ae4f848cbe
< 1.0.9
MEDIUM 5.3 Directory traversal vulnerability in meb_download.php in the myEASYbackup plugin 1.0.8.1 for WordPress allows remote att… wordfence
559cbc69-85b6-4bad-9bb2-26d64195ba7e
< 2.1.1
MEDIUM 5.3 The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized lo… wordfence
559ade81-73cd-4820-a6db-9323d1d82f8f MEDIUM 5.3 The Payday plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
5596a0f0-6bfe-4c6e-a0d6-117e13117098
< 1.0.2
MEDIUM 5.3 The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization c… wordfence
55924ea3-373c-4297-a958-5670def1f6c0
< 3.9.10
MEDIUM 5.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refe… wordfence
55801141-9b3d-4dc3-84b5-2a85dfbcde74
< 2.4.2
MEDIUM 5.3 The Sitewide Notice WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
554bea9d-903f-4e6f-8013-9816aa375f70
< 2.5.5
MEDIUM 5.3 The Residential Address Detection plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
552bc1cc-df98-4608-a50e-db1381ca8e0a
< 3.4.15
MEDIUM 5.3 The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to IP Address Spoo… wordfence
550872c8-3663-48fa-ab3f-f90351f3e169
< 2.25
MEDIUM 5.3 The Relevanssi – A Better Search (Pro) plugin for WordPress is vulnerable to Sensitive Information Exposure in version… wordfence
54f939f9-2853-401a-adc0-5b727da5179b
< 3.1.8
MEDIUM 5.3 The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Informati… wordfence
54f7cdb7-4e92-4793-86bb-cbd612e7ec13
< 2.4.2
MEDIUM 5.3 The Post Timeline plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
54bcd95e-52a8-49fb-9526-eb39549b5182
< 6.20
MEDIUM 5.3 The Ebook Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… wordfence
54bc98e8-5cde-4310-9d61-ebea828b5093
< 1.4.0
MEDIUM 5.3 The Contact Form Widget – Contact Query, Contact Page, Form Maker, Query Table plugin for WordPress is vulnerable to S… wordfence
← Prev 1189 1190 1191 1192 1193 1194 1195 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top