🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1199 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4913a764-8fe5-4ca1-ba03-27243b1822fe
< 6.5.39
MEDIUM 5.3 The YOP Poll plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
490dd84f-7c03-43c7-b4e1-167fa2b15c03
< 1.1.28
MEDIUM 5.3 The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booki… wordfence
48f9cbcb-b565-4de7-a5df-8dac7a4b7e63
< 3.0.1
MEDIUM 5.3 The GravityView plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includ… wordfence
48e3b90c-5af3-4538-95c6-fc8864b51db2 MEDIUM 5.3 The Image Cleanup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… wordfence
48dc10a9-7bb9-401f-befd-1bf620858825
< 1.1.0
MEDIUM 5.3 The Coming Soon & Maintenance Mode by Colorlib plugin for WordPress is vulnerable to Information Exposure in all version… wordfence
48cc0c28-77e2-49e7-aba3-fea2e66f7bb8
< 6.16.5.1
MEDIUM 5.3 The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
48ab8363-bc1c-47b4-8eb4-6093cd7591c9
< 5.5.7
MEDIUM 5.3 The Zero Spam for WordPress plugin for WordPress is vulnerable to spam protection bypass in all versions up to, and incl… wordfence
48a6fe41-675a-4033-877b-77e6cd906f73
< 2.1.1
MEDIUM 5.3 The Run Contests, Raffles, and Giveaways with ContestsWP plugin for WordPress is vulnerable to Sensitive Information Exp… wordfence
489fe6ac-5437-44a2-93dc-00e75eefbc45
< 1.3.0
MEDIUM 5.3 The FeedFocal plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
489931ef-bac3-4de8-84ec-6f226d96f778
< 3.6.16
MEDIUM 5.3 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to arbitrary file uploads d… wordfence
489256a8-e28f-4d7c-895a-928e9463bb1b
< 2.0.9.3
MEDIUM 5.3 The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in vers… wordfence
48871c87-1997-4d15-b0d7-2fdc61190f3b
< 2.1.3
MEDIUM 5.3 The Views Counter plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
4855627a-de56-49ee-b0b0-01b9735d8557
< 4.4.3
MEDIUM 5.3 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medic… wordfence
484ffb38-584e-4239-a9db-2d6d9dfb250a
< 3.4.1.0
MEDIUM 5.3 The Nota Fiscal Eletrônica WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
484d364d-cf33-4575-a10b-6b0815f12a69
< 1.9.6
MEDIUM 5.3 The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
483fa12f-cdd1-4d11-8cec-f3ffc4fdcc88
< 5.15.0
MEDIUM 5.3 The Avada Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
483dad33-bde9-4008-b79c-6a66d3514652
< 2.7.3
MEDIUM 5.3 The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Path Traversal in all ver… wordfence
4836b2c8-c552-425e-8c4d-fdcdf795e14a
< 1.2.6
MEDIUM 5.3 The The Conference theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
481bbdd6-9546-4c1f-a4ec-023ad7b37217
< 3.0
MEDIUM 5.3 The BackupBuddy plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.2.28 v… wordfence
47f9a466-2826-4835-b06e-14cf4ceb7567
< 7.6.7
MEDIUM 5.3 The Zigaform plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.6.… wordfence
47f57e90-94c9-4c9c-8700-bf591f6539ec
< 7.0.4
MEDIUM 5.3 The Analytify Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… wordfence
47dac5bb-45c8-4d10-93e3-938df3e920f9 MEDIUM 5.3 The Yaad Sarig Payment Gateway For WC plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
47bb46df-3ed6-4331-8c05-c76331aa6995
< 0.4
MEDIUM 5.3 The Paid Memberships Pro CCBill Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to i… wordfence
47b0a994-0460-44fb-bebd-d09efc69a8f3
< 4.3.2
MEDIUM 5.3 The Visual Feedback, Review & AI Collaboration Tool For WordPress – Atarim plugin for WordPress is vulnerable to unaut… wordfence
478e3383-2e5c-48e2-85f4-10503bda40ab MEDIUM 5.3 The WP Customize Login Page plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
← Prev 1196 1197 1198 1199 1200 1201 1202 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top