πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1194 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5268485f-d912-4c2d-a0ad-aabb69f9c98c
< 3.0.0
MEDIUM 5.3 The Seriously Simple Podcasting plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up … wordfence
52632b50-9755-4ebd-a1a8-587cc633debb
< 12.8.4
MEDIUM 5.3 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Insecure Direct Object Refere… wordfence
5258480a-3954-4620-84bf-8a711ba62d0a
< 1.7.2
MEDIUM 5.3 The REST API Log plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, … wordfence
525626be-fe1d-4543-91a1-ae5ea3658862
< 2.121
MEDIUM 5.3 The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, an… wordfence
524715f3-0016-4008-ba41-4ba60899ab88
< 2.1.23
MEDIUM 5.3 The Cozy Blocks – Page Builder for Gutenberg & Site Editor with Post Blocks, WooCommerce Blocks, Magazine Blocks & Wor… wordfence
52454f57-0b23-4c5f-b100-9b1fcdf00c21 MEDIUM 5.3 The IDonatePro - Blood Donation, Request And Donor Management WordPress Plugin plugin for WordPress is vulnerable to una… wordfence
523f7a8a-d06d-4778-be14-d0b7ca32dab3
< 1.1.6
MEDIUM 5.3 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a… wordfence
5231b741-4d02-45b5-b2aa-0d9d3536a416
< 4.1.2
MEDIUM 5.3 The BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encycloped… wordfence
52223cd1-ee0d-484c-a2af-179b54bfc115 MEDIUM 5.3 The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to… wordfence
521168c2-dcbb-44fc-9ca1-d3358185b32d MEDIUM 5.3 The EMI Calculator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
51ff2654-fa38-4807-87f5-53a9996839c1 MEDIUM 5.3 Multiple cross-site scripting (XSS) vulnerabilities in vcc.js.php in the Verification Code for Comments plugin 2.1.0 and… wordfence
51e3a976-a1a3-411a-b88c-f1cb2aa8d5eb
< 6.7.1
MEDIUM 5.3 The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disc… wordfence
51df33a7-d04d-4c47-aba8-d174e2a40170 MEDIUM 5.3 The Outranking Plugin Options plugin for WordPress is vulnerable to unauthorized access in all versions up to, and inclu… wordfence
51d98277-a1d7-4708-8daf-88948a235375
< 1.4.9
MEDIUM 5.3 The WP Super Cashe plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.4.8 du… wordfence
51aa5531-e5b3-4c47-8d06-58eac6dd92fb
< 18.5.4
MEDIUM 5.3 The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capa… wordfence
5176d862-577b-4a37-9da3-9ba106f77d6e
< 4.7.6
MEDIUM 5.3 The email-users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜post_id’ parameter in … wordfence
5175573f-1ba8-4d15-8419-7c65f1db4490
< 1.2.12
MEDIUM 5.3 The The Stockie Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc… wordfence
51564b26-0d7c-4499-9f5a-84f76c5a5e8a MEDIUM 5.3 The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0… wordfence
5145b6bf-a726-4ef8-964f-63504bf7107e MEDIUM 5.3 The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in … wordfence
512e042e-c280-4966-b41c-ce589ca035af
< 4.6.6
MEDIUM 5.3 The Video Conferencing with Zoom plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
50d7edfe-3b87-428b-b774-f414a684c8e9
< 3.0.0
MEDIUM 5.3 The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to 2FA bypass in all versions … wordfence
50ca7cf8-bb47-42ea-badc-8bfe0328cbb0
< 1.1.0
MEDIUM 5.3 The Download Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
509f7ea5-6b69-492d-a4e6-77b4e1f4de4a MEDIUM 5.3 The StyleAI plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
509cccbd-3aa0-45f1-84a0-387d678ebf65
< 9.0.35
MEDIUM 5.3 The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in ver… wordfence
5098e74a-9a99-48b3-9f44-b780bfdeb24e
< 5.1.0.3
MEDIUM 5.3 The Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin plugin for WordPress… wordfence
← Prev 1191 1192 1193 1194 1195 1196 1197 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top