πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1214 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2db29c12-bf8a-4d5a-b12a-6c74b816d5f0
< 3.5.4.9
MEDIUM 5.3 The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up … wordfence
2da883bf-5741-4eda-8a93-3b7feb90f4c6
< 1.4.2
MEDIUM 5.3 The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … wordfence
2d9f9774-e45d-4b69-80e0-dce1e7c0ea78
< 3.5.0
MEDIUM 5.3 The Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Pop… wordfence
2d9d3588-9c71-485a-9183-3d1d4a936e03
< 2.11.33
MEDIUM 5.3 The Welcart e-Commerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to 2.11.33 (exclusive). T… wordfence
2d8cbc6e-cb75-4d7b-94a5-876c57cf3329 MEDIUM 5.3 The Social Share Buttons for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
2d8ae431-04cd-49e4-a5ea-ea7b1263c836 MEDIUM 5.3 The Caulk theme for WordPress is vulnerable to Sensitive Data Exposure in all versions. This could allow unauthenticated… wordfence
2d7d83f6-92d1-43a8-821c-7b9470ead493
< 3.4.27.1
MEDIUM 5.3 The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field. wordfence
2d790b52-bb2e-4bfa-bca1-34c0df721571
< 6.1.1
MEDIUM 5.3 The Course Booking System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
2d7330ac-22c6-48a7-91ab-66e2ec639964
< 9.2.07.002
MEDIUM 5.3 The WP Photo Album Plus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
2d5e247c-ec80-4d25-9fb3-dd17a3724a70 MEDIUM 5.3 The Printeers Print & Ship plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.… wordfence
2d532ffc-c6f1-41e3-9a59-0706802ab8e2 MEDIUM 5.3 The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct… wordfence
2d36c088-d512-4c9a-a1bc-47a4ee597d63 MEDIUM 5.3 The Aardvark plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
2d24aa7e-bbf1-4a54-b53b-7a37e613e0e6
< 3.4.3
MEDIUM 5.3 The Rate my Post – WP Rating System plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, a… wordfence
2d1302c4-7aeb-49f4-aa11-2c0e08bd9c71
< 3.8.7.2
MEDIUM 5.3 Cross-site scripting (XSS) vulnerability in wpsc-admin/display-sales-logs.php in WP e-Commerce plugin 3.8.7.1 and possib… wordfence
2ce8da99-a150-473f-9136-50e42833bb9a MEDIUM 5.3 The Arcane theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
2cdacd01-0eae-4f38-9ecc-170a1a6e7d56 MEDIUM 5.3 The Final User plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
2cd92497-25ac-4560-82ed-e21a117d8c64
< 1.3.3
MEDIUM 5.3 The Newsmatic theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
2cc9f75d-f1a6-486b-b924-76ec618c5314
< 2.0.74
MEDIUM 5.3 The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… wordfence
2cc27239-1464-4dba-99a2-4784e230ca48
< 4.4.6
MEDIUM 5.3 The sailing theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
2cbc0b70-c8a4-4924-a67f-cea81ab19cdc
< 1.1.1
MEDIUM 5.3 The Branded Social Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
2cb276a2-131b-4ce2-9968-2007ce9cdc93 MEDIUM 5.3 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
2caff643-77a5-4951-80ac-177671c30fba
< 1.1.9
MEDIUM 5.3 The Internal Linking of Related Contents plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
2ca879be-ac35-4bc6-b3f4-a6e8fdf02875 MEDIUM 5.3 The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to IP Address Spoofing in all v… wordfence
2c9cf461-572c-4be8-96e6-659acf3208f3
< 4.0.12
MEDIUM 5.3 The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… wordfence
2c931bd2-8c19-4211-9378-f32a1302defd MEDIUM 5.3 The User Activity Log plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial … wordfence
← Prev 1211 1212 1213 1214 1215 1216 1217 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top