πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1208 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3a19bd0c-87b3-421b-a7af-c473ac084813
< 5.8.1
MEDIUM 5.3 The WP Travel Engine – Best Travel Booking WordPress Plugin plugin for WordPress is vulnerable to price manipulation i… wordfence
3a13d1d5-3e40-4b38-bf29-0e589682d0c4 MEDIUM 5.3 The Post Cloner plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
3a0c8ecc-f0a1-41fa-a5f7-2d65d610efc0
< 1.7.8
MEDIUM 5.3 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
39f8c830-9f71-4ca6-8fcc-54769cef878f
< 2.2.6
MEDIUM 5.3 The Semper Fi All in One SEO Pack plugin before 2.2.6 for WordPress does not consider the presence of password protectio… wordfence
39e0fd33-4071-4510-a7d5-b499a8a3543c
< 5.6.0
MEDIUM 5.3 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… wordfence
39d8ea75-3cef-4ba9-b0ee-62a58599a350
< 1.1.1
MEDIUM 5.3 The WCBoost – Products Compare plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… wordfence
39d19c40-e191-4c2d-bd77-411e571604d2
< 1.2.16
MEDIUM 5.3 The Terms & Conditions Per Product plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
39bcc1af-0315-44e0-864a-4105cedd216c
< 1.8.12
MEDIUM 5.3 The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) plugin … wordfence
39adc110-dd99-4447-9d72-2f78e7ebd2cf
< 4.4.12
MEDIUM 5.3 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Full Path Disclosure in all versions… wordfence
39a410a6-ce8b-498c-855c-8cbb7d4b875b
< 7.0.0
MEDIUM 5.3 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to unauthorized access due to… wordfence
398a75b1-6470-44b3-aaea-d5e8b10db115 MEDIUM 5.3 The Vzaar Media Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
395b016f-018c-458d-a585-34f3de3eae5c
< 3.4.4
MEDIUM 5.3 The Yet Another Stars Rating plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ch… wordfence
395692e0-b165-46a2-a15c-059e9f7d2ac2
< 1.9.6
MEDIUM 5.3 The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
39543965-fa15-4169-ae99-582c49b629ab MEDIUM 5.3 The IDPay Payment Gateway for Woocommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve… wordfence
3936479e-7503-4bf2-8080-70e95be45f73
< 3.4.3
MEDIUM 5.3 The WordPress CRM Plugin – WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
391b8d9e-c57c-44d8-a060-c1b94a191522
< 2.5.3
MEDIUM 5.3 The Five Star Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized access due to a missi… wordfence
39193ebd-005a-4497-9939-99947323a1a0
< 1.14.12
MEDIUM 5.3 The TelSender plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
38fd8881-94f6-4330-a519-7582e253e057
< 3.2.83
MEDIUM 5.3 The Download Manager plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, … wordfence
38f09a45-2b11-47c7-af16-c7f9c3a46e0e MEDIUM 5.3 The Build & Control Block Patterns – Boost up Gutenberg Editor plugin for WordPress is vulnerable to unauthorized acce… wordfence
38e8275f-477e-4d07-85b0-8bca71cd7089
< 2.1.2
MEDIUM 5.3 The WP Datepicker plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
38bf5451-5042-48ad-a189-699e1e7abf07
< 10.45
MEDIUM 5.3 The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to unauthorized access due t… wordfence
38b9a64f-a83a-4c0f-88df-383652fde986
< 1.5.2
MEDIUM 5.3 The iPages Flipbook plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … wordfence
38b63167-e1a6-4279-97cf-900df0651f20
< 4.7.27
MEDIUM 5.3 WordPress Core is vulnerable to Sensitive Information Exposure in versions between 4.7.0 and 6.3.1 via the User REST end… wordfence
38b2b477-5b8a-42c2-b346-57707d9a34a5
< 6.1.6
MEDIUM 5.3 The Course Booking System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability … wordfence
389364b7-4ab9-41b2-86f0-d30393e08146 MEDIUM 5.3 The RT-Theme 18 Responsive WordPress Theme plugin for WordPress is vulnerable to Sensitive Information Exposure in all v… wordfence
← Prev 1205 1206 1207 1208 1209 1210 1211 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top