πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1217 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
291b44d1-c63c-4278-b344-a361f88e82d1
< 4.7.16
MEDIUM 5.3 The MasterStudy LMS Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
29137748-91b1-4b01-9f05-63da592e941a
< 2.2.12
MEDIUM 5.3 The WP Club Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
2903d15c-4f4d-497c-b6ed-4ae32c047a8a
< 7.6.10
MEDIUM 5.3 The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, a… wordfence
28f22a48-7445-4104-9b76-60520e7a290e
< 6.4.2
MEDIUM 5.3 The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized access due… wordfence
28d9ab98-c1ab-45ee-a371-6598a8347b10 MEDIUM 5.3 The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to unauthorized modification of… wordfence
28ca9590-dc0b-40c9-9de6-1480094ea8be
< 2.14.18
MEDIUM 5.3 The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Infor… wordfence
28bcaf28-bb75-4d55-9e9b-afa760fc793e
< 2.7
MEDIUM 5.3 wp-admin/upgrade.php in WordPress up to and including 2.6.1, allows remote attackers to upgrade the application, and pos… wordfence
28a7b80c-8282-4f5c-b442-d6bce9fda25d MEDIUM 5.3 The Ripe HD FLV plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.1 via … wordfence
28a3f382-3801-4e98-9004-56c27a85f0a2
< 5.7.9
MEDIUM 5.3 The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a mis… wordfence
2880cde0-a278-4a41-97f7-c54c2b3aceb2
< 2.4.30
MEDIUM 5.3 The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… wordfence
2866122e-158e-4a60-9f80-3d88832bedc0
< 2.2.0
MEDIUM 5.3 The Raychat plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
2862d7d6-4e27-4138-b4aa-789351edeac3 MEDIUM 5.3 The Voting Contest plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
28206bc1-008f-407e-b1c9-e318abe09438
< 2.3.0
MEDIUM 5.3 The Endless Posts Navigation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
281a1c0e-bbd8-4cf6-94ca-b888c7d7e3af
< 10.14.11
MEDIUM 5.3 The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… wordfence
280e9ba9-57a9-45ce-820c-c34cac41b350
< 3.1.2
MEDIUM 5.3 The Events Made Easy plugin for WordPress is vulnerable to Payment Bypass in versions up to, and including, 3.1.1. This … wordfence
280da91d-f97e-49ad-811d-849943c8a9f1
< 19.12.1
MEDIUM 5.3 The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to unauthorized access due to a… wordfence
27e4d519-bc98-44d3-a519-72674184e7f2
< 3.2.11
MEDIUM 5.3 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Informat… wordfence
27e3dfe3-ad33-4d0c-a999-d0734df2f59b
< 5.104.0
MEDIUM 5.3 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, … wordfence
27d0f627-aeee-46de-a319-861af00fdbf4
< 7.2.8
MEDIUM 5.3 The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauth… wordfence
27ca93a1-3dfc-4bbd-834a-1c04d9e22ebf
< 1.2.2
MEDIUM 5.3 The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized acce… wordfence
27c728eb-db40-41e1-b73b-243661b15970 MEDIUM 5.3 The Add Product Frontend for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
279cebb5-4be4-485a-92c7-e0bcc961f93e
< 2.6.1
MEDIUM 5.3 The Fat Rat Collect plugin for WordPress is vulnerable to unauthorized action due to a missing capability check on the w… wordfence
2791bbd5-9101-4484-a352-0e4d2ce04e5d
< 6.1.0
MEDIUM 5.3 The Xendit Payment plugin for WordPress is vulnerable to unauthorized order status manipulation in all versions up to, a… wordfence
27517985-374a-40ef-8a90-575dfc9335f3 MEDIUM 5.3 The Fix Media Library plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… wordfence
2750936e-d366-44f2-82d2-74188261466e
< 1.5.13
MEDIUM 5.3 The Panda Pods Repeater Field plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
← Prev 1214 1215 1216 1217 1218 1219 1220 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top