πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1202 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4419f975-fb8d-4603-9e16-122fbd7cfdae
< 1.7.7
MEDIUM 5.3 The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to unauthorized access due to a… wordfence
440e2618-5b45-4bad-8a97-2fb1a6e991ea
< 1.4.0
MEDIUM 5.3 The Backup Bolt plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… wordfence
4402fb12-326b-4332-83e6-493a65743c61
< 2.2.4
MEDIUM 5.3 The Audio Editor & Recorder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … wordfence
43f38a87-ac2c-4b5a-9559-d529c4b2799c
< 3.9.6
MEDIUM 5.3 The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any au… wordfence
43f34d3b-ed55-48d1-9074-b33f166e333e
< 3.16.6
MEDIUM 5.3 The 12 Step Meeting List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and… wordfence
43daaaf7-8086-448a-be99-ee1959ef0fb4
< 5.4.9
MEDIUM 5.3 The Woffice Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
43d8904f-3bc9-4c67-b44b-8d78762b6b30
< 3.6.1
MEDIUM 5.3 The WP Private Content Plus plugin for WordPress is vulnerable to information disclosure in all versions up to, and incl… wordfence
43d1264a-2265-4423-a643-7ef6436d3764
< 3.30
MEDIUM 5.3 The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and includ… wordfence
43c781c3-dc3e-4258-b594-689d0035cab0
< 3.7.5
MEDIUM 5.3 wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 all… wordfence
439ce99c-79d3-4e1c-8f6e-7f68b017ac8c MEDIUM 5.3 The The E-Commerce ERP: Purchasing, Inventory, Fulfillment, Manufacturing, BOM, Accounting, Sales Analysis plugin for Wo… wordfence
438dfea4-21f1-4796-9c1b-81aebd8842f2
< 5.27.6.1
MEDIUM 5.3 The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
4360f293-201c-40c1-9603-931d72cc79bc MEDIUM 5.3 The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
432ac3b1-8f1d-442f-8e8d-62a1f26ba259
< 3.4.1
MEDIUM 5.3 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… wordfence
4319fa2e-8826-4100-9156-cbe80582367e
< 3.4.9.4
MEDIUM 5.3 The WP-Members Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i… wordfence
42dacd44-f676-4d2d-ad7d-9dc5b4af6d8a
< 2.0.9
MEDIUM 5.3 The All In One Login β€” WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login… wordfence
42cd1b53-400f-4933-b3cc-2fd9079e241c
< 2.3.8
MEDIUM 5.3 The WP Express Checkout (Accept PayPal Payments) plugin for WordPress is vulnerable to price manipulation in all version… wordfence
42aa82ff-0d37-4040-b8fc-84d29534a4b7
< 4.2.8.5
MEDIUM 5.3 The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including… wordfence
428feddb-c8c3-49a7-8e01-dc548c184229
< 1.24.7
MEDIUM 5.3 The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to… wordfence
4279efe9-df57-405a-85a0-6c22e912662c
< 4.7.0
MEDIUM 5.3 The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the… wordfence
426554d8-e6dc-496f-adce-61a22880a4c2
< 3.71.0
MEDIUM 5.3 The FG Drupal to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a… wordfence
4261bc62-a091-408b-8643-e6fa61d62103
< 2.2.23
MEDIUM 5.3 The WPCafe plugin for WordPress is vulnerable to unauthorized access, modification, or loss of data due to a missing cap… wordfence
424cf586-f225-4ce3-9b66-b0bece394f1f
< 3.1.1
MEDIUM 5.3 The wpForo Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
424b0de2-98ac-434f-98be-d2b0eec308ce MEDIUM 5.3 The Saoshyant Page Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
41de0cf6-d093-4c33-8123-a097ba3e0add
< 1.7.6
MEDIUM 5.3 The TrackShip for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
41db1af4-7a49-4d10-8538-151d3bb7af8f
< 3.1.4
MEDIUM 5.3 The avalex – Automatisch sichere Rechtstexte plugin for WordPress is vulnerable to unauthorized access due to a missin… wordfence
← Prev 1199 1200 1201 1202 1203 1204 1205 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top