πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1213 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2ffd6393-6604-48d9-ba22-7d989305e9ed MEDIUM 5.3 The Riaxe Product Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,… wordfence
2ff9570f-fca5-4e10-80ae-822608b6dd9d
< 1.2.168
MEDIUM 5.3 The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
2ff30e1f-bb02-441c-bda7-af3fe9d4b5d8 MEDIUM 5.3 The Responsive Posts Carousel WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missin… wordfence
2fd8c981-081c-4671-ad1e-3caf004669dd
< 1.8.0
MEDIUM 5.3 The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… wordfence
2fd7d6af-a938-4106-aed2-12b9a5454da9
< 1.2
MEDIUM 5.3 The secure-files plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1 via… wordfence
2f91a7c3-ee0e-48e9-aa5f-dfc1160bbc09
< 4.7.6
MEDIUM 5.3 The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4… wordfence
2f6eb792-aa01-4118-a7b3-e4ef50d6bcaf
< 7.2.7
MEDIUM 5.3 The WooCommerce Anti-Fraud plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
2f51c73c-0eea-43b1-afae-ee8e8708a3d3
< 4.9.3
MEDIUM 5.3 The YITH WooCommerce Product Add-Ons plugin for WordPress is vulnerable to Content Injection in all versions up to, and … wordfence
2f499d5e-eb27-4611-af27-ac9fd6a9f044
< 2.0.80
MEDIUM 5.3 The Accept Stripe Payments plugin for WordPress is vulnerable to Content Injection in all versions up to, and including,… wordfence
2f32bf1e-acc7-4fbc-a448-75227dcced1d
< 3.5.0
MEDIUM 5.3 The Payoneer Checkout plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
2f2ab0ba-6212-4466-835f-763ea01336b9
< 2.11.1
MEDIUM 5.3 The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Paym… wordfence
2f12fa00-6108-4bd4-9310-8558211f4d0f
< 1.2.3
MEDIUM 5.3 The Campay Woocommerce Payment Gateway plugin for WordPress is vulnerable to Unauthenticated Payment Bypass in all versi… wordfence
2f127fe5-67b8-40e1-a916-c607410b08b3
< 1.0.34
MEDIUM 5.3 The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check o… wordfence
2edbcf13-4cf8-46dd-a21e-1e5898ed4e50
< 1.2.19
MEDIUM 5.3 The Better Chat Support for Messenger plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
2ecec7d7-d1b2-4ccf-ade6-1f78224968c6
< 1.7.1057
MEDIUM 5.3 The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … wordfence
2eae7c33-2347-4b34-8b5f-7f4a6ee3e9c1
< 3.0
MEDIUM 5.3 The Sunshine Photo Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and in… wordfence
2ea32997-9fe3-4f31-9c3a-28bc14af3713
< 4.1.23
MEDIUM 5.3 The Google XML Sitemaps plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
2e933356-1faf-4766-9554-aad618052d83
< 1.2.48
MEDIUM 5.3 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordP… wordfence
2e90f61b-a74b-4f9f-a8ba-ea9ba3fa9987
< 2.5.0
MEDIUM 5.3 The Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress plugin for WordPress is v… wordfence
2e69d666-50de-4c82-9ad4-9ed40fcc7218
< 6.4.6.1
MEDIUM 5.3 The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable t… wordfence
2e56e810-3884-4d2c-85c5-7d4ec8e27652
< 6.0.2
MEDIUM 5.3 The Food Menu – Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress is vulnerable to unauthorized a… wordfence
2e25557d-577b-4ac6-a006-43079ab4b77d
< 2.8.169
MEDIUM 5.3 The GeoDirectory plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, … wordfence
2e093d1f-9c5a-44f8-bc27-9c320e220358
< 5.38.2
MEDIUM 5.3 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mi… wordfence
2df8570b-c1a2-4a1b-b4d4-fe7a75eb05b6
< 1.1.4.4
MEDIUM 5.3 The BEAR plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th… wordfence
2dea1bcb-14c2-4ec9-8a4d-087bac2db486
< 7.5.0
MEDIUM 5.3 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure… wordfence
← Prev 1210 1211 1212 1213 1214 1215 1216 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top