πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1205 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3f421fcc-f2e4-43d4-b170-2e3383fe0ad7
< 4.9.6
MEDIUM 5.3 The WpStream – Live Streaming, Video on Demand, Pay Per View plugin for WordPress is vulnerable to unauthorized access… wordfence
3f408f1f-207e-427a-a5d0-d0fadf453d7e
< 2.0.74
MEDIUM 5.3 The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… wordfence
3f3c556d-8baf-4d75-a331-51b76ee084ee
< 6.2.0
MEDIUM 5.3 The Breadcrumb NavXT plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including 6.1.… wordfence
3f1cf77a-64b4-405b-adcb-ef16d9e82ab2
< 3.1.0
MEDIUM 5.3 The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and inclu… wordfence
3ef4f85f-9b8d-4cac-acf6-6b8cd9b63722 MEDIUM 5.3 The AS English Admin plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.0.0. Th… wordfence
3ee538dd-466b-471d-8055-af32ecfdfc77
< 3.6.6
MEDIUM 5.3 The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to unau… wordfence
3edb95f1-aa82-4b51-957e-2039dd8624e1
< 7.3.1
MEDIUM 5.3 The Titan Anti Spam & Security plugin for WordPress is vulnerable to protection bypass due to improper IP validation in … wordfence
3ec761eb-6bd9-4c19-a98d-cb4738922a84
< 1.1.2
MEDIUM 5.3 The Gravity Forms: Multiple Form Instances plugin for WordPress is vulnerable to Full Path Disclosure in all versions up… wordfence
3e9b6514-e727-42fe-8893-a317b71b2760
< 1.2.6
MEDIUM 5.3 The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Missing Authorization in all versions up… wordfence
3e90a515-d164-4468-b2be-22c8f1039c4a
< 3.16.6
MEDIUM 5.3 The 12 Step Meeting List plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
3e8d9909-7b98-4d98-8293-0c30eebc6c7b
< 2.22
MEDIUM 5.3 The Gift Up Gift Cards for WordPress and WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
3e82448a-43d8-4a01-a576-08e289b67442
< 2.7.5
MEDIUM 5.3 The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
3e772760-f390-417f-82d0-f415a6ef837d MEDIUM 5.3 The Login Block IPs plugin for WordPress is vulnerable to IP Address Spoofing in versions up to and including 1.0.0. Thi… wordfence
3e66230c-dbe0-43a9-a292-250ccf06931f
< 2.2.13
MEDIUM 5.3 The Telegram Widget and Join Link plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
3e5f3eac-d2da-43ea-9303-731d78102372
< 3.2.9
MEDIUM 5.3 The Restrict Content plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the … wordfence
3e5b00da-4182-4777-aa8e-bc9cd3f3883f MEDIUM 5.3 The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
3e41ab01-836f-4658-ab2e-c56c7cb2feb4
< 1.2.6
MEDIUM 5.3 The Restaurant and Cafe theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
3df8a0a2-e248-4c2e-a9c2-b5afc79cdd2a
< 1.5.4
MEDIUM 5.3 Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows a… wordfence
3de82328-e44f-4488-a2ae-1dd2c3b8a502
< 1.22.4
MEDIUM 5.3 The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabili… wordfence
3dae466b-c81a-4000-b40b-6b9fd0c7a30f
< 1.0.11
MEDIUM 5.3 The HAPPY – Helpdesk Support Ticket System plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
3d9b3ca6-1f75-41d1-9d78-fc9e1c92b66a
< 2.4.17
MEDIUM 5.3 The Kali Forms β€” Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to unauthorized access due to… wordfence
3d9332be-2cf0-46cd-81e4-6436aeec0f83
< 2.18.1
MEDIUM 5.3 The NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerc… wordfence
3d68293a-b98b-41e0-9f79-ccd2c0108e82 MEDIUM 5.3 The illi Link Party! plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
3d604f7a-947c-43f4-bba6-e7e98b2d7844
< 5.9.16
MEDIUM 5.3 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
3d5c8946-22d3-4631-a030-e1556b4824d8
< 1.0.9
MEDIUM 5.3 The Chat On Desk Order Notifications – WooCommerce plugin for WordPress is vulnerable to Two-Factor Authentication Byp… wordfence
← Prev 1202 1203 1204 1205 1206 1207 1208 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top