πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1226 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1abf0bbd-c502-4db8-9e01-413517082dd8
< 1.10
MEDIUM 5.3 The WordPress Exit Box Lite plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and … wordfence
1aae04fc-1bd8-4a0f-a481-032c17640c8b
< 5.4.9
MEDIUM 5.3 The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to Sensitive Information Exposure in al… wordfence
1a9ff565-ce51-4888-92c0-d7d3a096fde1 MEDIUM 5.3 The SrbTransLatin – Serbian Latinisation plugin for WordPress is vulnerable to Sensitive Information Exposure in all v… wordfence
1a815110-888e-419d-bcad-745c4efec1ef
< 4.9.0
MEDIUM 5.3 The CoCart plugin for WordPress is vulnerable to Payment Bypass in versions up to, and including, 4.8.0. This is due to … wordfence
1a657a1d-3b01-444c-af4e-c9ebebfbc01a
< 2.7.10
MEDIUM 5.3 The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized ac… wordfence
1a54f8cc-cadb-4496-bcc4-ef8387b72300
< 3.3.30
MEDIUM 5.3 The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc… wordfence
1a3ca502-177e-4337-93e3-347c773d2761
< 7.4
MEDIUM 5.3 The Events Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including… wordfence
1a3037cd-43b8-4f6e-a3e5-b8c48d2a0dbe
< 1.8.12
MEDIUM 5.3 The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) plugin … wordfence
1a2f0d07-33bb-4d68-9c81-61f13a004804
< 1.0.8
MEDIUM 5.3 The Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin for WordPress is vulnerable to unauthorized acc… wordfence
1a12f472-0ae1-4c3c-b7e3-85f637fe58c5 MEDIUM 5.3 The Easy Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an… wordfence
19f8a656-696c-4e4f-a0a6-c71010a1ee12
< 2.5.14
MEDIUM 5.3 The Wallet System for WooCommerce – Wallet, Digital Wallet, Cashback, Recharge User Wallets, Partial Payments, Wallet … wordfence
19db591b-1e59-4ff7-b339-bea869083bbc
< 1.0.3
MEDIUM 5.3 The ReviveNews theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
19b159ca-4b41-48b4-880d-9b9dc44b3463
< 3.1.0
MEDIUM 5.3 The LottieFiles – Lottie block for Gutenberg plugin for WordPress is vulnerable to Sensitive Information Exposure in a… wordfence
19ad787d-e027-48f5-8b5f-9263338b4fc3
< 1.74.0
MEDIUM 5.3 The Memberful plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… wordfence
19aa5070-2336-4139-a05c-ca6f1a1a0e30 MEDIUM 5.3 The 1-Click Backup & Restore Database plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
19a6b19c-244d-4b30-8db2-b4d06a5f5509
< 1.2.7
MEDIUM 5.3 The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to un… wordfence
19a3d5a5-4673-41e7-9868-99699852f330 MEDIUM 5.3 The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to IP Address Spoofing in all versi… wordfence
19958187-7eb1-479e-bd36-d40974ae65ca
< 1.0.2
MEDIUM 5.3 The Block IPs for Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
197efd6a-b0f4-459d-b7e5-f8ff5b5e3003
< 1.2.50.0
MEDIUM 5.3 The MailOptin plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the clear_… wordfence
1958c166-282d-4469-b79d-4e959e0492c1
< 1.2.1
MEDIUM 5.3 The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification and loss of data due to missi… wordfence
195788de-129e-4112-bcab-a7835c8164ca
< 1.5.7
MEDIUM 5.3 The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
19565648-d080-416e-b421-5cd08a7c62ab
< 2.4
MEDIUM 5.3 The CF7 7 Mailchimp Add-on plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
19235851-bea5-46ec-92cd-8d800e1aa23a
< 4.39.0
MEDIUM 5.3 The Web Push Notifications – Webpushr plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers… wordfence
19233e1d-fcbe-4391-a7a7-03524698ab18
< 1.4.0
MEDIUM 5.3 The Benevolent theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
191ec7ea-6ca7-4943-8709-f372ae5a81c7
< 2.3.2
MEDIUM 5.3 The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all version… wordfence
← Prev 1223 1224 1225 1226 1227 1228 1229 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top