ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1207 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3bd5652e-1c26-4952-9119-1d7f7eff7d55 MEDIUM 5.3 The Diet Calorie Calculator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
3bd3e797-5e31-4f54-a28f-2525fb5e367e MEDIUM 5.3 The WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit plugin for WordPress is vulnerable to Sensitive Information… wordfence
3bc9f344-b605-4257-8d77-e073f85fe344
< 2.7.5
MEDIUM 5.3 The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification… wordfence
3bb15611-85a4-4efb-81e5-7352c348c4a9
< 2.0.29
MEDIUM 5.3 The Blocksy Companion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
3ba3cf12-facb-479b-8077-fd279c40607e
< 1.3.81
MEDIUM 5.3 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized access of data due to a miss… wordfence
3b6b1b7e-2ba4-4b72-9e3d-b54c00437cac
< 2.33.2
MEDIUM 5.3 The GiveWP plugin for WordPress is vulnerable to unauthorized donation form access due to a missing check on the handleB… wordfence
3b5fc0ac-7a33-48da-8b0f-566b9eb0f17f
< 0.17
MEDIUM 5.3 The If Menu plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
3b44d23c-4872-491f-8a91-b0feb888ac54
< 3.1.3
MEDIUM 5.3 The WP Dummy Content Generator plugin for WordPress is vulnerable to unauthorized modification of data due to missing ca… wordfence
3b2f8726-c4c4-4ed6-aa8d-4412cf5be061
< 7.8.6
MEDIUM 5.3 The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form … wordfence
3af5f238-9b2f-47d0-89e6-30ac09227041
< 6.0.9.4
MEDIUM 5.3 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … wordfence
3aecea73-d905-428f-95e5-40f18db09edc
< 1.2.0
MEDIUM 5.3 The Bopo – WooCommerce Product Bundle Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in … wordfence
3ae457da-a276-4bca-ae3f-c2f3e4fc45a0 MEDIUM 5.3 The WP Genealogy – Your Family History Website plugin for WordPress is vulnerable to unauthorized access due to a miss… wordfence
3acab2e6-c6ce-4e87-aa6d-ce9d027cd774
< 1.7.07
MEDIUM 5.3 The Booking Package plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
3aa1964e-97e9-4166-89d5-788b336790b6 MEDIUM 5.3 The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check… wordfence
3a998de7-fa46-495c-a4ca-15df4e59457f
< 3.3.2
MEDIUM 5.3 The Block Plugin Update plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
3a7e8afa-d250-41b1-aa34-555fb458e359
< 2.13
MEDIUM 5.3 Multiple plugins for WordPress are vulnerable to Sensitive Information Exposure in various versions via invoices. This m… wordfence
3a7524ce-cd8c-45af-b07b-616f63a62bd5
< 3.5.0
MEDIUM 5.3 The Everest Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including,… wordfence
3a703fc4-6c61-442e-a637-515e9f501575
< 5.6.4
MEDIUM 5.3 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… wordfence
3a6221e3-e26b-46b2-8e67-b2afe65bc3d9 MEDIUM 5.3 The Paymob for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
3a4c36d4-5d0f-4e73-b356-0b7326fcb524
< 2.7.6
MEDIUM 5.3 The Smush Image Compression and Optimization plugin before 2.7.6 for WordPress allows directory traversal. wordfence
3a442498-0f80-4373-a90c-155966c04945 MEDIUM 5.3 The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to una… wordfence
3a3597fa-71e2-4753-b226-5d95e576947a MEDIUM 5.3 The Store Locator Plus® for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi… wordfence
3a337765-b6ea-4c2a-9f1a-e408a9444b88
< 7.3.15.727
MEDIUM 5.3 The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription lis… wordfence
3a1f192c-de8d-47e7-8055-bb64394e9a29 MEDIUM 5.3 The Chaplin theme for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.6.8. This i… wordfence
3a1d0432-aff0-477e-aa6e-4de3e4d789cb MEDIUM 5.3 The Simple User Capabilities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… wordfence
← Prev 1204 1205 1206 1207 1208 1209 1210 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top