πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1200 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
478d7c1e-35b9-4796-8ccd-eb02591a3a17
< 3.0.7
MEDIUM 5.3 The wpForo Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
4775d8f0-ae3b-41aa-a0d2-4284840f66f1
< 1.3.8
MEDIUM 5.3 The Car Rental Manager – Online Vehicle Booking System plugin for WordPress is vulnerable to unauthorized access due t… wordfence
47681954-37ed-493b-b4da-9e9032e561b3
< 2.4.3
MEDIUM 5.3 The got (JS Package) is vulnerable to Open Redirect in versions up to, and including, 11.8.4 as well as from 12 to below… wordfence
4756312e-2e34-4524-b978-fa37e3cafd1f
< 1.2
MEDIUM 5.3 The Awesome Responsive Photo Gallery – Image & Video Lightbox Gallery plugin for WordPress is vulnerable to unauthoriz… wordfence
4735c491-9595-42b8-bb1c-1b18c89fcf7a
< 5.2
MEDIUM 5.3 The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosur… wordfence
471e1080-e9bc-4241-ae71-8bfeac94b0b4 MEDIUM 5.3 The Job Board Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
470fb8d4-3d60-4a8e-a89b-2d64203c1f0b
< 4.2.2
MEDIUM 5.3 The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Sensiti… wordfence
470d64e6-9dd5-4069-8b16-ea26a3b9f0e1
< 1.3.4
MEDIUM 5.3 The The Tribal Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… wordfence
46b6dd7d-cbf7-4e8b-8ff5-347b966d8689 MEDIUM 5.3 The Realbig plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
46a36f2b-c352-4d76-b4c4-8a73ec5dd910
< 0.1.6
MEDIUM 5.3 The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all version… wordfence
467a9b16-b57c-417c-b4e1-9f3edc80b5df
< 1.6.3
MEDIUM 5.3 The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to authorization bypass due to a missing ca… wordfence
4677042d-ff0a-4340-ada7-c82d2da0c01c
< 3.3.0
MEDIUM 5.3 The Klarna Payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
4662a842-88ba-4f01-8009-7248792d485b MEDIUM 5.3 The Fascinate theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
4661566b-0729-4489-9a47-8e3e0ac73573 MEDIUM 5.3 The Addonify Floating Cart For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
4653f0fd-5369-4e3c-9bce-3f4200c0bddb
< 2.5.5
MEDIUM 5.3 The DELUCKS SEO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
46525a06-f3a4-4c78-ba32-4b937e1dbac6
< 1.15.21
MEDIUM 5.3 The Form Maker plugin for WordPress is vulnerable to Captcha Bypass in versions up to, and including, 1.15.20 due to ins… wordfence
464a41f6-5569-4306-be99-566e2354c73b
< 2.8.2
MEDIUM 5.3 An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plug… wordfence
4638516e-d36f-4f31-9ed5-f733aeae03e2
< 2.4.1
MEDIUM 5.3 The Hestia Nginx Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on th… wordfence
461993a3-8d47-4c9e-8f5f-78058d96ab2a
< 1.9.1
MEDIUM 5.3 The Patreon WordPress plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and inclu… wordfence
46186f8d-e50c-476a-9480-b6121412474a
< 2.1.0
MEDIUM 5.3 The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up … wordfence
46122be7-5e88-4656-8944-a747f5cdc69e
< 1.1.1
MEDIUM 5.3 The CookieHub plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
4609e1a8-c766-4054-a5d0-eabff1089300
< 5.1.3
MEDIUM 5.3 The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom… wordfence
4607dca0-d3b7-4fca-8f89-a0a739bd7551 MEDIUM 5.3 The Birth Chart Compatibility plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and incl… wordfence
45f1e4b9-5ffb-4dca-aa79-09c664b46f00
< 1.6.17
MEDIUM 5.3 The LocateAndFilter plugin for WordPress is vulnerable to unauthorized access of data due to insufficient verification o… wordfence
45ccc116-866e-467f-8ebb-8a3b6589c069 MEDIUM 5.3 The Slek Gateway for WooCommerce plugin for WordPress is vulnerable to Information Exposure in version 1.0. This is due … wordfence
← Prev 1197 1198 1199 1200 1201 1202 1203 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top