πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1222 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
20be9a37-9e9f-4791-a27c-e0db007be787
< 2.7.4
MEDIUM 5.3 The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback,… wordfence
20b31652-02af-4c1a-a3c8-a4cca69c8ae2
< 7.0
MEDIUM 5.3 The BulletProof Security plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and… wordfence
2097ab8b-6f7b-4a64-b31a-be3a09ae12bf MEDIUM 5.3 The WP Translate – WordPress Translation Plugin plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
20813a6f-672e-4c06-a5a6-737483f4d402
< 4.8.2
MEDIUM 5.3 The Featured Image from URL plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… wordfence
207eedfc-8b42-49be-be7a-98da38ad7ee6
< 6.1.14
MEDIUM 5.3 The Simple File List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
20641b8d-3742-4088-bb29-ed54056fa229 MEDIUM 5.3 The Flowbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
203950f3-f327-4d9e-afcf-8467aab23712
< 3.1.1
MEDIUM 5.3 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sen… wordfence
20203ff8-34ff-496c-b51c-8cad3ded8bf7
< 2.2.28
MEDIUM 5.3 The Autopay dla WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
201b25bb-b39f-4fb7-b5d7-ca9fe9dd89e0 MEDIUM 5.3 The Direct Checkout for WooCommerce Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
2006dc4c-ec1a-45ab-94a3-1f86d80e70ca
< 1.1.28
MEDIUM 5.3 The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all ve… wordfence
2002b29b-c817-48a9-b65c-ad1bff2c0935
< 2.3.3
MEDIUM 5.3 The Object Cache 4 everyone plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … wordfence
1fe97ac1-cab9-4b6f-bddd-bdcdc9faee40 MEDIUM 5.3 The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized acce… wordfence
1fdd0a4c-ce47-44bc-b9a5-a8f2af12da85
< 3.0.0
MEDIUM 5.3 The EventPrime plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.… wordfence
1fd9d526-8d3a-423c-99de-78bff95d24c5
< 2.8.1
MEDIUM 5.3 The Job Postings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
1fd0b13c-7447-45da-9608-80b7629d9bbf
< 3.13.7
MEDIUM 5.3 The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up t… wordfence
1fce54b1-e1e6-4742-9eb3-bbfb613ccd70
< 1.0.9
MEDIUM 5.3 The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… wordfence
1fc4eaec-b5d8-4707-9260-bac02a4b1866
< 2.2.8
MEDIUM 5.3 The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… wordfence
1fa8dba0-0227-428d-a6de-c4247c40e481
< 2.4.10
MEDIUM 5.3 The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capabili… wordfence
1f72a309-8ef8-4943-8e64-38bb7909397a
< 2.5.0
MEDIUM 5.3 The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
1f5c6cc0-5026-4903-a96a-db4ec3258ad2
< 3.1.1
MEDIUM 5.3 The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object … wordfence
1f589345-a081-4d27-ac4a-6edc44b96f91
< 10.2.1
MEDIUM 5.3 The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a … wordfence
1f42b3fc-cb2a-4e95-a55b-608ae64d8b58
< 6.1.0
MEDIUM 5.3 The WordPress Popular Posts plugin for WordPress is vulnerable to Unauthenticated Views Changes in versions up to, and i… wordfence
1f3ab230-f6e2-4150-a4af-178da8c244dd MEDIUM 5.3 The Grand Restaurant WordPress theme for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
1f2845a5-7572-4533-8949-08bee99fca20
< 2.0.6
MEDIUM 5.3 wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remo… wordfence
1ef2a04a-de2c-4421-876a-aec5093f8970
< 1.9.9.8
MEDIUM 5.3 The WPLMS Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
← Prev 1219 1220 1221 1222 1223 1224 1225 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top