πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1204 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4077dd33-bd3c-4369-b9ed-b6b6b017248d
< 6.8.5
MEDIUM 5.3 The Travel Engine plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and includin… wordfence
40725a33-353e-443a-b1f1-ac7c3e4a1323
< 1.1.6
MEDIUM 5.3 The Coachify theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
40588454-66f3-4c84-98b4-11b81e019908
< 5.0.11
MEDIUM 5.3 The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to unau… wordfence
40570bb7-1638-4305-876e-86ad4c336944
< 1.4.8
MEDIUM 5.3 The WordPress Backup & Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… wordfence
4051a7f1-0564-41eb-8ef4-0ee1c8af57cb MEDIUM 5.3 The Clockinator Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
4048ae11-fece-42aa-baf3-c636c4875635
< 1.4.6
MEDIUM 5.3 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to authorization bypass due… wordfence
4045575a-35f0-46e5-afb7-93eee9be3a97 MEDIUM 5.3 The Infinite-Scroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
4031f857-9712-4f4a-93e8-0b01f9a9c32d
< 0.9.9
MEDIUM 5.3 The Database Cleaner: Clean, Optimize & Repair plugin for WordPress is vulnerable to Sensitive Information Exposure in a… wordfence
402f1f9f-35c7-4304-891b-a07f3e84c189
< 2.7.5
MEDIUM 5.3 The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up … wordfence
4000c0e4-6ffd-4161-b488-429e0e863f68
< 1.0.45
MEDIUM 5.3 The Appointment Booking Calendar – WP Timetics Booking Plugin plugin for WordPress is vulnerable to unauthorized acces… wordfence
3ff90774-f5f6-4d9c-9565-1cff31f9bec4 MEDIUM 5.3 The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers… wordfence
3ff3c560-26b6-4139-97dc-670ea9b8bb33
< 4.11.0
MEDIUM 5.3 The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vu… wordfence
3fe1313c-1368-4bcb-9d11-25b948da5547 MEDIUM 5.3 The Advanced Text Widget plugin for WordPress is vulnerable to unauthorized admin notice dismisssal due to a missing ca… wordfence
3fc683c5-6939-4750-aba2-0e1f3b33ab5a
< 3.7.40
MEDIUM 5.3 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthor… wordfence
3fbda86c-188c-4705-a7eb-77b201f91a18 MEDIUM 5.3 The Nuss - Hotel Booking WordPress theme for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
3fa78f4e-ede2-4863-a2d7-99bd8c7b5912
< 2.25.2
MEDIUM 5.3 The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and… wordfence
3fa5ddd8-8166-45eb-9576-8683c1d12cc6 MEDIUM 5.3 The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a mi… wordfence
3fa1afa6-f9b5-4153-ab0b-8fd5291f63d7
< 3.6.4
MEDIUM 5.3 The Virtuaria PagBank / PagSeguro para Woocommerce plugin for WordPress is vulnerable to unauthorized access due to a mi… wordfence
3fa0dbad-fc00-46f1-bcc4-b41116d1c4ae
< 2.3.12
MEDIUM 5.3 The ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for … wordfence
3f95c288-7710-46aa-898b-a923afa7a4ab
< 1.8.3
MEDIUM 5.3 The AI Power: Complete AI Pack – Powered by GPT-4 plugin for WordPress is vulnerable to unauthorized access due to a m… wordfence
3f82427e-5731-4694-8d90-4d14c01f19fb
< 1.8.17.0
MEDIUM 5.3 The WP Mailster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… wordfence
3f7088ce-961c-4cf3-ab94-3ef9a626006b
< 1.6.0
MEDIUM 5.3 The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist plugi… wordfence
3f6412bf-65ec-445f-a1fe-27aeb8330712
< 8.4.6
MEDIUM 5.3 The Soledad theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
3f6058e2-a5ec-43b2-9cb7-9efcf0853ffc
< 1.10.36
MEDIUM 5.3 The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized a… wordfence
3f445e0e-c32d-4c46-85ac-fa21f99d30ec MEDIUM 5.3 The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to Sensitive Informa… wordfence
← Prev 1201 1202 1203 1204 1205 1206 1207 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top