πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1225 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1c8de019-4ec1-49fd-9b0b-c2b1b6908ba8 MEDIUM 5.3 The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax… wordfence
1c8b8391-8d18-49ad-a5ee-2ba7a9090e6b
< 1.5.4
MEDIUM 5.3 The Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery plugin for WordPress is vulnerable to unauthorized ac… wordfence
1c4fcaa5-357a-4b70-8653-3874a234f07d
< 5.4.4
MEDIUM 5.3 The kk Star Ratings plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.4.3. T… wordfence
1c2b9858-eb0c-42bd-bc32-c58c0f809fc8
< 1.1.10
MEDIUM 5.3 The Networker - Tech News WordPress Theme with Dark Mode theme for WordPress is vulnerable to unauthorized modification … wordfence
1c220091-4094-4f72-aaf1-a426f07aef5b
< 10.30.12
MEDIUM 5.3 The Salon Booking System Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
1c0d18d3-8758-41ae-b104-dac69eee4ac9
< 1.1.2
MEDIUM 5.3 The TH Side Cart and Menu Cart for Woocommerce plugin for WordPress is vulnerable to unauthorized plugin settings update… wordfence
1c09fa88-8981-414e-ad24-7460b81ea295
< 3.14.0
MEDIUM 5.3 The Seriously Simple Podcasting plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
1befba2d-cd16-48d1-8499-d848a649cf9d
< 1.3.3
MEDIUM 5.3 The Spa and Salon theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
1bbbec13-50ea-4dd1-ab6e-f44814813edb
< 1.2.8
MEDIUM 5.3 The Book Landing Page theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
1bb25412-8f63-4a9d-84bd-44fac59c6eed
< 1.1.8
MEDIUM 5.3 The YourMembership Single Sign On – YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due… wordfence
1b9f3e68-b069-4f41-87a1-ffaa287215b9
< 6.11.6
MEDIUM 5.3 The Simple:Press Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on th… wordfence
1b8d866e-e187-4ff5-bed7-b03e2a213c11
< 4.4.5
MEDIUM 5.3 The Church Admin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… wordfence
1b847857-5dc9-4793-b9d6-759f27377fe3
< 2.2
MEDIUM 5.3 The Void Elementor Post Grid Addon for Elementor Page builder plugin for WordPress is vulnerable to unauthorized modific… wordfence
1b693646-efdb-44c7-a8d8-48315d19fe23 MEDIUM 5.3 The EduBlink theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
1b54ce63-ea6e-40e0-a66b-9a08e81f77be MEDIUM 5.3 The WDV One Page Docs plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
1b4eb0a1-69ad-4e0d-9760-752ec0589314
< 2.0.8
MEDIUM 5.3 The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image ga… wordfence
1b245791-6aac-4ee3-9278-5b7c01f13263
< 3.43.0
MEDIUM 5.3 The WP Fusion Lite – Marketing Automation and CRM Integration for WordPress plugin for WordPress is vulnerable to Sens… wordfence
1b21bdfd-42ec-43fe-b581-04276b86c50b MEDIUM 5.3 The Rupantorpay plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
1b1268ae-51b0-4243-9cc8-c8564c121ff2
< 3.7.21
MEDIUM 5.3 The iZooto plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
1b05191b-4f4a-487a-9fbf-843a4787511e MEDIUM 5.3 The CGC Maintenance Mode plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including,… wordfence
1b00e42b-9c03-4a3c-86b7-1552f7700b2f
< 1.1.6
MEDIUM 5.3 The CRM Perks Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
1afb94ab-b3ba-4598-8ff4-f9ffc6717371
< 1.52.1
MEDIUM 5.3 The Forminator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.52.0. … wordfence
1af442f7-b57c-47bd-9733-5e6bb5c89443
< 5.4.6
MEDIUM 5.3 The kk Star Ratings plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability … wordfence
1add47ea-6a7b-443a-b31d-3bb6c0d5d72d
< 2.11.0
MEDIUM 5.3 The Drag and Drop Multiple File Upload PRO plugin for WordPress is vulnerable to Path Traversal in versions up to, and i… wordfence
1ac39498-3171-4d91-a911-381c8ed751dc
< 3.9.2
MEDIUM 5.3 getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read … wordfence
← Prev 1222 1223 1224 1225 1226 1227 1228 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top