πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1211 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
33ff3b63-d634-43b1-9199-5fb6216dca48
< 19.9.9.2
MEDIUM 5.3 The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to Sensitive In… wordfence
33f8f75d-c57e-456c-a48a-82fa668adb1c
< 6.5.29
MEDIUM 5.3 The YOP Poll plugin for WordPress is vulnerable to captcha bypass due to a reusable captcha bypass in the validateImage … wordfence
33e94bb9-71e4-4af8-aa8d-5972b5be1aea
< 10.9.2.1
MEDIUM 5.3 The Thrive Leads Version plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
33c666af-b51f-4d9e-9c32-ca0a124cd4b7
< 2.5
MEDIUM 5.3 WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 … wordfence
33c23ad3-7d4f-4e2d-b28e-a402b1355480 MEDIUM 5.3 The WP Vault plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.8.6.6 via th… wordfence
33a8173e-cb1a-4396-a05b-7404bf899ad9
< 1.9.12
MEDIUM 5.3 The My Tickets plugin for WordPress is vulnerable to authorization bypass due insufficient validation of a users payment… wordfence
33a5838b-2cec-4b47-ac0c-577f090e8041
< 2.3.0
MEDIUM 5.3 The Smart Coupons For WooCommerce Coupons plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
3391740a-c859-47a2-9a55-b8bdc57daec3 MEDIUM 5.3 The AhaChat Messenger Marketing plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and i… wordfence
336f4272-135c-4601-84fe-087390dbf5ef
< 3.8
MEDIUM 5.3 The BSK PDF Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl… wordfence
33486414-6878-4b16-ae2d-00ec52fc2213
< 7.8.6
MEDIUM 5.3 The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to authorization bypass… wordfence
332a37fa-a082-4f6b-a81f-9741b121d0a0
< 1.2.0
MEDIUM 5.3 The Document Library Lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an… wordfence
32f55a78-b5ed-496b-b173-575b8867e410
< 1.2.5
MEDIUM 5.3 The Travel Diaries theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
32dc0914-b5a3-49f2-86ed-3bc9de6cc974 MEDIUM 5.3 The Manual - Documentation, Knowledge Base & Education WordPress theme for WordPress is vulnerable to unauthorized acces… wordfence
32da1015-338f-422f-a777-12b5bee8152d
< 3.2.1
MEDIUM 5.3 The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
32d0f709-192a-4d9f-bfe9-15c1be4c4b95
< 5.3.1
MEDIUM 5.3 The iThemes Security plugin for WordPress is vulnerable to insecure backup and logfile generation in versions up to, and… wordfence
32ce92b9-8c9c-4a7e-9580-00a564500e30
< 6.19.9
MEDIUM 5.3 The Website Builder by SeedProd β€” Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for W… wordfence
32cce973-bc3b-45f1-ad4d-ff395d3a6c8e MEDIUM 5.3 The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu… wordfence
32b49654-26f6-4b83-8851-92e04408e8b2
< 2.0.18
MEDIUM 5.3 The radcliffe-2 theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
329ad5dc-9339-4540-aba3-f21a78a74d4b
< 2.8.2
MEDIUM 5.3 The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
328a4d88-afa2-4305-a8e5-73e626e9f53f
< 4.6.8
MEDIUM 5.3 The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i… wordfence
3281d6eb-9f14-43d4-a4d4-532993039e53
< 3.0.0
MEDIUM 5.3 The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including,… wordfence
326e168d-c2ae-485f-93ff-ed59d5b6061e
< 20.8.1
MEDIUM 5.3 The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable… wordfence
325813f3-c893-4e98-ad99-452ff63d5e18
< 32.0.21
MEDIUM 5.3 The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to Content Injection in all versions up t… wordfence
324c747e-35b2-4d56-bd00-7591669b24b9
< 1.5.4
MEDIUM 5.3 The WebToffee WP Backup and Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio… wordfence
323436b5-fbfe-4923-8b08-93c1fcabc016
< 3.9.0
MEDIUM 5.3 The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
← Prev 1208 1209 1210 1211 1212 1213 1214 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top