πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1221 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
22175f1f-1dc0-45a1-a72e-3135ea6de7fc
< 1.5.4
MEDIUM 5.3 The Pixelavo – Server Side Tracking & Pixel + AI Ads Tools plugin for WordPress is vulnerable to unauthorized access d… wordfence
2212585b-1437-40a8-a5da-5b5c9f88c365
< 1.2.1
MEDIUM 5.3 The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authoriza… wordfence
220ca462-6a5b-440e-badf-d253e2b6b1f0
< 2.2.8
MEDIUM 5.3 Multiple plugins and/or themes for WordPress are vulnerable to unauthorized modification of data due to a missing capabi… wordfence
22076415-c093-4c8f-b7bc-108d203185e3
< 6.8.2
MEDIUM 5.3 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthoriz… wordfence
220487de-2a1c-47ec-ac65-db1af44aed3d
< 4.2.6
MEDIUM 5.3 The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up t… wordfence
21f917a4-efee-421b-98b1-a9b18c7527d2
< 1.1.5
MEDIUM 5.3 The AtomChat plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… wordfence
21ec0fc9-4fb2-43fd-aba5-8f452d35d7b8
< 1.23
MEDIUM 5.3 WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive informat… wordfence
21dcb733-0477-46b3-a409-9823c03cbdca
< 2.1.47
MEDIUM 5.3 The Blocksy Companion Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … wordfence
21d79573-59af-44e4-b9b0-7fc712bae48c
< 2.11.0
MEDIUM 5.3 The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
21ccb2cc-6ae2-4a2e-9daa-3f0d57caedce
< 1.0.28
MEDIUM 5.3 The Syncee Premium Dropshipping & Wholesale plugin for WordPress is vulnerable to unauthorized access due to a missing c… wordfence
21b59c8c-671a-45a9-8774-d059c4ad15ba
< 5.0.4
MEDIUM 5.3 The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauth… wordfence
21a1a6c2-0eb1-4ee3-abf0-76b84adca01b
< 7.9.1
MEDIUM 5.3 It is possible to bypass the hidden login page functionality in iThemes Security < 7.9.1 and iThemes Security Pro < 6.8.… wordfence
218e68b5-57a9-4d2f-9a13-4d159e12dbd9
< 2.13.5
MEDIUM 5.3 The Klarna Checkout for WooCommerce plugin for WordPress is vulnerable to Denial of Service in all versions up to, and i… wordfence
21690b9c-ffec-4195-8c0f-2b1801552bc6
< 1.1.17
MEDIUM 5.3 The Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress plugin for WordPress is vulnerable to SQL… wordfence
2163af55-1ea4-4c60-b9f0-baf99297c6bc
< 3.4.2.1
MEDIUM 5.3 The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up … wordfence
2162601a-3b94-4d6b-959e-99ba68d1271a MEDIUM 5.3 The EleForms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
21618fba-3f57-43b2-b9ea-13484301755d
< 3.11.3
MEDIUM 5.3 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is… wordfence
21552524-9f3f-4ef1-b8bc-9eb6ebfaac12
< 3.0.22
MEDIUM 5.3 The LeadConnector plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
2152b820-2eb1-4f08-ab3f-10bd2692eea5
< 2.0.4
MEDIUM 5.3 The Salesmate Add-On for Gravity Forms plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
2116340a-160f-493c-abe3-75b05282d78a
< 3.5.2
MEDIUM 5.3 The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vul… wordfence
20f31e48-0dbb-498a-a400-681cacea7c9c
< 5.0.9
MEDIUM 5.3 The Contact Form for Plugin by Fluent Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in ve… wordfence
20ecc8ea-305c-49a2-bb1e-35624b16e1f5 MEDIUM 5.3 The WP SecureSubmit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl… wordfence
20e51573-d555-4928-87df-ea5f5ca70848 MEDIUM 5.3 The Jetpack Feedback Exporter plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to… wordfence
20d744a0-ae5f-4a16-8736-bb3a2cb6d881
< 5.29.0.1
MEDIUM 5.3 The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
20d5848e-7772-45dc-ad6f-edb9164c8d44
< 2.5
MEDIUM 5.3 The MP3-jPlayer plugin for WordPress is vulnerable to Path Disclosure in versions before 2.5. wordfence
← Prev 1218 1219 1220 1221 1222 1223 1224 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top