πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1227 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
190c8744-b8e0-4722-ae0a-f18d7c058dfe
< 14.2.2
MEDIUM 5.3 The Latest Post Shortcode plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
190a21cd-9716-4a57-a793-63309c339427
< 4.5.0
MEDIUM 5.3 The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized m… wordfence
190492ec-5982-4dce-9e97-16a518a01a27 MEDIUM 5.3 The Chapa Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in… wordfence
18f7664b-6e2b-4422-8d6e-5bc4e6611069
< 5.4.33
MEDIUM 5.3 The Woffice CRM theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
18e2263c-7945-4dc8-9a58-fb86167fbeed
< 1.2.3
MEDIUM 5.3 The Hydra Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
18be0679-7083-4189-b3fe-5ec6cd2e6f76
< 1.17.0
MEDIUM 5.3 The Booking Activities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
1896885a-a104-464a-bb57-2c3c73ff9415 MEDIUM 5.3 The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to unauthorized data export due to a missing… wordfence
1892b510-abac-4282-b0f6-69da46ec1c8d
< 1.4.0
MEDIUM 5.3 The Admin Safety Guard plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and inclu… wordfence
189259d3-b591-4b8c-8423-e220c6bab265 MEDIUM 5.3 The Acerola - Ultra Minimalist Agency Theme theme for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
188d1e4e-9fd6-4a26-920b-a0a9f203f9d1
< 8.73
MEDIUM 5.3 The IdeaPush plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
1831f7b0-3425-4ee9-ae64-25a5728fa83b MEDIUM 5.3 The AIO Performance Profiler, Monitor, Optimize, Compress & Debug plugin for WordPress is vulnerable to Sensitive Inform… wordfence
181e351f-7dc8-4bef-a746-4736413601a8 MEDIUM 5.3 The elfsight Contact Form widget plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… wordfence
180a0111-984d-4563-91ea-6f75c3210056
< 3.1.0
MEDIUM 5.3 The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to unauthorized access due… wordfence
17f7be7f-f675-4c9f-a7b3-525a3c3c5775
< 1.3.9.1
MEDIUM 5.3 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in a… wordfence
17f4d448-d9d8-4bee-b216-42f9b77c30be
< 3.9.4
MEDIUM 5.3 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulne… wordfence
17f17cae-f444-4fa1-9090-ec6ea267ef2e
< 2.8.2
MEDIUM 5.3 The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… wordfence
17d5253c-5000-40c7-a7fd-f75d4badfb5e
< 3.3.31
MEDIUM 5.3 The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the d… wordfence
17d1b133-99ec-4dfa-83d4-189606989cb6
< 7.6.7
MEDIUM 5.3 The Bonus for Woo plugin for WordPress is vulnerable to insufficient input validation in all versions up to, and includi… wordfence
17cbcf67-f10d-41bc-acf7-98e5d99b50af
< 3.4.0
MEDIUM 5.3 The EventPrime plugin for WordPress is vulnerable to unauthorized modification of data due to improper input validation … wordfence
17b0366c-f170-420d-b0d5-5c2f9f9e1cca
< 2.4.5
MEDIUM 5.3 The Chatbot with ChatGPT WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capa… wordfence
17a4bd5c-0cd3-46e4-b6ee-edf87f0e92ca MEDIUM 5.3 The WCP Contact Form plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capability c… wordfence
17906039-0130-4e24-b932-1ba19d3d58ff
< 3.0.2
MEDIUM 5.3 The Maintenance Mode plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 3.0… wordfence
177929c5-d32f-4f0a-afc1-6d4a7091dfd5
< 1.5.5
MEDIUM 5.3 The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. pl… wordfence
17646179-47ad-4846-a581-3e713df43c32
< 3.7.15
MEDIUM 5.3 The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via un… wordfence
1754293e-ed27-4b5e-92f3-aea23127e0bc
< 2.8.1
MEDIUM 5.3 The Exclusive Addons Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, a… wordfence
← Prev 1224 1225 1226 1227 1228 1229 1230 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top