πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1220 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
23d5e2ba-3a8a-4ded-aba9-fa0a7228a398
< 1.8.1
MEDIUM 5.3 The Slideshow Gallery LITE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a… wordfence
23d49ee8-9afb-479a-85e7-a83cd5ae5186
< 1.7.9
MEDIUM 5.3 The WooCommerce POS – Point of Sale plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
23a9b6ee-55d9-4e44-926b-f253e83ca78c MEDIUM 5.3 The HomeFix Elementor Portfolio plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
23a1dad4-599e-4d3f-b1d5-c77ec1bbcf22
< 4.0.8
MEDIUM 5.3 The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie C… wordfence
2389f614-a9e6-479c-a713-71271d3a35c6
< 2.2.13
MEDIUM 5.3 The Sign-up Sheets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
234df811-92d9-4645-b242-eb2c09bc6202
< 6.1.8
MEDIUM 5.3 The Awesome Support plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
233f3415-9d4f-4ddb-af69-55c832ff67a1
< 4.3.8
MEDIUM 5.3 The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration plu… wordfence
233aab46-ec09-4c26-b4fc-2f095c225754
< 2.3.9
MEDIUM 5.3 The Everest Backup plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
231f1e11-661d-40e4-a139-0ee2be95d551
< 3.2.13
MEDIUM 5.3 The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
2305462c-0a00-4423-8dc2-e32628c4864d
< 7.8.11
MEDIUM 5.3 The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modif… wordfence
22f58318-90ce-4f98-991c-1270d6768f5c MEDIUM 5.3 The Register Plus plugin 3.5.11 and earlier for WordPress allows remote attackers to obtain sensitive information via a … wordfence
22f54e4b-2f9a-40b2-b1d2-38f046b71a05
< 2.162
MEDIUM 5.3 The MyCryptoCheckout – Bitcoin, Ethereum, and 100+ altcoins for WooCommerce plugin for WordPress is vulnerable to unau… wordfence
22e1be31-7a05-4089-9830-c27b70176e76 MEDIUM 5.3 The EscortWP theme for WordPress contains a backdoor in all versions up to, and including, 3.6.2. This makes it possible… wordfence
22b17fcb-0c97-462d-b67c-6da2919478d5
< 1.30.1
MEDIUM 5.3 The Social Pug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
22a73d1a-02ba-4453-a2c8-0b79a75313f6
< 4.9.0
MEDIUM 5.3 The CoCart – Headless REST API for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a miss… wordfence
2294251f-ef51-4ef7-ad7a-905cc2bc00b3
< 3.3.9
MEDIUM 5.3 The Yet Another Stars Rating plugin for WordPress is vulnerable to vote tampering in versions up to, and including, 3.3.… wordfence
228a3c72-fbb0-48bc-8066-6ca954a14421
< 1.64
MEDIUM 5.3 The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to unauthorized modification of data du… wordfence
2283b147-b904-4086-8cb1-6d8969ccbaf6
< 1.50.3
MEDIUM 5.3 The Forminator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
228079da-3c69-423c-b69b-f1a670258772 MEDIUM 5.3 The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.8… wordfence
22738841-b25c-4519-9b94-e64a3fdf6cea
< 2.1.0
MEDIUM 5.3 The Minimum and Maximum Quantity for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a miss… wordfence
226c312e-38f0-4dac-bf5a-bce6df24aacc
< 2.2.1
MEDIUM 5.3 The Pixel Tag Manager for WooCommerce – Google Analytics 4, Google Ads, and More Pixels plugin for WordPress is vulner… wordfence
224a3ca4-954e-4e39-adc7-2a37d1a7a026 MEDIUM 5.3 The Javo Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
22345e9c-e654-4c72-b452-ed340f9ef6c1 MEDIUM 5.3 The GDPR Cookie Notice plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
223373fc-9d78-47f0-b283-109f8e00b802 MEDIUM 5.3 The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticate… wordfence
222f9d6b-2b97-4531-b085-bf3c8f9d89d7
< 4.8.122
MEDIUM 5.3 The Masterstudy - Education WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
← Prev 1217 1218 1219 1220 1221 1222 1223 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top