πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1229 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
153cb585-4eea-4959-85b1-2487be11f116
< 1.3.7.8
MEDIUM 5.3 The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Ex… wordfence
15349295-4ee7-4746-ae34-200ffd24aa82
< 2.3.0
MEDIUM 5.3 The Wp Ultimate Review plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che… wordfence
1508ae48-099c-44a2-a1c8-000a5e5acbef
< 6.6.4.2
MEDIUM 5.3 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to unauthorized access … wordfence
14fede14-bdf1-41e1-8ea9-188acbb41aa1
< 1.3.0
MEDIUM 5.3 The Move Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
14f665ba-b312-4167-a235-8d6aa3fbace9 MEDIUM 5.3 The The Norebro Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc… wordfence
14dcc17f-8252-44d0-ba31-f12f7f53593a MEDIUM 5.3 The Realty Workstation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
14d2198a-4117-4182-9b03-9fa463da03d9 MEDIUM 5.3 The Essential Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
14b7fd1e-6e2d-49bb-8492-b072afeebd88
< 3.7.17
MEDIUM 5.3 wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random nu… wordfence
14b6f5b6-66ab-4c47-853e-7551fad39478
< 20220216
MEDIUM 5.3 Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115 wordfence
149ef56e-b9a6-4d28-9c90-0e2fa917ada6
< 3.15.0
MEDIUM 5.3 The Avada (Fusion) Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
14993c04-7fe3-4c42-a605-2e431df14d79
< 1.0.8
MEDIUM 5.3 The Restrict for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a… wordfence
1497a6e4-fc4a-4f12-bd89-01d468ccd128
< 9.1.5
MEDIUM 5.3 The Payment Gateway for PayPal on WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
147c8d60-1ed1-4d01-8160-7d500b30ab98
< 2.2.22
MEDIUM 5.3 The Breeze Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
141c33be-36f5-4db6-92f7-f04fa647af08
< 1.1.8
MEDIUM 5.3 The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
13fb7904-8641-43ae-bcfe-00ca5416e949
< 3.0
MEDIUM 5.3 The LoginPress Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
13cce634-42ee-46c2-98c1-009749ac0d37
< 1.1.5
MEDIUM 5.3 The Digital Download theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
13a206ea-0890-4535-9da7-54a7a45f0452
< 2.7.4
MEDIUM 5.3 The White Label CMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
13981037-e698-42a7-9471-e27486cf1a4e
< 1.4.5
MEDIUM 5.3 The WP Super Cache plugin for WordPress is vulnerable to Directory Listing in versions up to, and including, 1.4.4. This… wordfence
138818d2-f66b-4503-9df6-b89765191d50
< 3.20.2
MEDIUM 5.3 The WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets plugin for WordPress is vulnerable to unauthoriz… wordfence
1375c43c-498f-4d68-ac9c-201592d26919
< 4.0.0
MEDIUM 5.3 The Disabler plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.3. T… wordfence
136f9667-ee76-4feb-9fc1-860cdb9e84cf
< 3.8.9
MEDIUM 5.3 The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
136ecfa1-5591-4636-bc30-6c68ddc7f277
< 3.0.14
MEDIUM 5.3 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of da… wordfence
135e55e0-c133-4b66-88ed-92e0083c53a5
< 5.6.8
MEDIUM 5.3 The LatePoint plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 5.6.7. This is… wordfence
135c33bb-5ec2-4697-9340-1d2651ff3a0b
< 4.11.54
MEDIUM 5.3 The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauth… wordfence
130c3bbf-19a9-4e11-b6f2-5a08bbf7b123 MEDIUM 5.3 The Mega Main Menu plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including… wordfence
← Prev 1226 1227 1228 1229 1230 1231 1232 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top