πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1209 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3892489e-6ff7-4664-bb06-b8edff6dd659
< 7.4.6
MEDIUM 5.3 The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all version… wordfence
387e7f52-8e17-4d4d-8479-1ff07ba036d3
< 1.52.0
MEDIUM 5.3 The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress … wordfence
384d690c-a1fd-4b97-9f7b-88b1ef1cee4f
< 1.5.0
MEDIUM 5.3 The Ghost plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4… wordfence
383c7837-e7b7-4608-9cdc-91b7dbc7f4e2
< 2.12.6
MEDIUM 5.3 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulner… wordfence
382837d9-ebc5-4200-bd7c-13e982ac921b
< 6.7.11
MEDIUM 5.3 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthoriz… wordfence
3826e2f8-3d91-4e07-84c8-8c88b374764b
< 0.9.107
MEDIUM 5.3 The WPvivid Backup and Migration plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
38257dbf-288e-4028-af65-85f5389888ac
< 6.0.6
MEDIUM 5.3 The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via th… wordfence
37f7f826-cb60-4e25-9a02-f18a0ace0a75
< 4.4.8
MEDIUM 5.3 The AWP Classifieds plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
37f0bc0c-4c34-43fb-9630-766cb20b2ccf
< 3.1.0
MEDIUM 5.3 The PhonePe Payment Solutions plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
37ec8e59-7b99-4f17-96d6-d1083dd9302f
< 5.0.27
MEDIUM 5.3 The Church Admin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
37e47649-3e58-475d-93ba-db9862a67f22 MEDIUM 5.3 The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to CAPTCHA Bypass i… wordfence
37de5734-7cf4-4289-ac07-9a40f31e9628
< 1.4.1
MEDIUM 5.3 The Gutenify – Visual Site Builder Blocks & Site Templates. plugin for WordPress is vulnerable to Sensitive Informatio… wordfence
37aedfb3-bc98-4a8f-bc19-af7778ff1a14
< 1.4.3
MEDIUM 5.3 The Media File Manager plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.4.2… wordfence
37aaf109-e04f-40d7-8303-a581b0b09d24 MEDIUM 5.3 The Owl Carousel plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability c… wordfence
379a5016-3968-4b28-8d6e-0f517e419016 MEDIUM 5.3 Multiple plugins for WordPress are vulnerable to malicious redirection in various versions. This is due to the use of Po… wordfence
37963064-77ad-4515-b801-5669ab8a3992 MEDIUM 5.3 The KI Live Video Conferences plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to… wordfence
3779cf95-9dfd-492b-b3a2-68dce3bb342d
< 3.0.8
MEDIUM 5.3 The WPCafe – Restaurant Menu, Online Food Ordering and Reservation Booking Solution plugin for WordPress is vulnerable… wordfence
370a96e0-f6be-4d55-b00f-eb4dc374fcb3 MEDIUM 5.3 The FAPI Member plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includ… wordfence
36fa7191-a4a9-40a5-896e-18e16525a5fb
< 4.1224
MEDIUM 5.3 The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to unauthorized ac… wordfence
36def628-e09e-4da0-ab14-35aefcb67f73
< 3.0.2
MEDIUM 5.3 The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… wordfence
36ccce3e-7d96-4a80-843e-041bc194812c
< 3.0.16
MEDIUM 5.3 The License Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versio… wordfence
36aa7193-0e31-4084-97d0-8c22ebff3f05
< 1.55.1
MEDIUM 5.3 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure… wordfence
36933547-2159-43f4-842d-750ff9e7b1dd
< 1.4.5
MEDIUM 5.3 The APPExperts – Mobile App Builder for WordPress | WooCommerce to iOS and Android Apps plugin for WordPress is vulner… wordfence
3681eb1a-df1e-4f30-99e0-0ff05664550c MEDIUM 5.3 The MF Plus WPML plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
3674cfb8-6372-4309-a9de-e6ef7c0b3836
< 5.9.0
MEDIUM 5.3 The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Basic Information Ex… wordfence
← Prev 1206 1207 1208 1209 1210 1211 1212 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top