πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1230 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
13088645-8233-40fb-8755-cbdf44c0eaf7
< 3.2.13
MEDIUM 5.3 The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions u… wordfence
12f9464b-d3d5-4000-8839-c63c77eca9b5
< 1.1.6
MEDIUM 5.3 The Ai Image Alt Text Generator for WP plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
12f7c109-2752-4584-99e4-d94dafe3e81a
< 2.1.2
MEDIUM 5.3 The Connector Wizard (formerly LC Wizard) plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
12da87e1-6a44-4b36-be7c-8d7ec51d71d7
< 1.46
MEDIUM 5.3 The FAQ / Accordion / Docs / KB – Helpie WordPress FAQ Accordion plugin plugin for WordPress is vulnerable to Sensitiv… wordfence
12d465d2-cd89-476e-b70a-743151a23053 MEDIUM 5.3 The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and includ… wordfence
12bf1cd8-cd55-4771-b2bb-597797b1b949
< 4.8.1
MEDIUM 5.3 The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. … wordfence
12a296db-ecc0-409b-8718-0c208504053a
< 2.1.5
MEDIUM 5.3 The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi… wordfence
128c6ab5-ddcf-4775-b390-db49da79e548
< 1.1.1
MEDIUM 5.3 The Sharable Password Protected Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio… wordfence
12837ce3-eeeb-4034-a90d-fc615056a818
< 3.1.2
MEDIUM 5.3 An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-securit… wordfence
123ac22c-545b-4deb-b31a-29f6dba15018
< 2.7.9
MEDIUM 5.3 The Easy Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
122b75d2-e882-45b9-baf1-acf847f8d60a
< 4.2.6.8.1
MEDIUM 5.3 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers… wordfence
12188a74-b1a6-4aa4-88b4-2d0d0dd32916
< 1.1.4.2
MEDIUM 5.3 Multiple plugins and/or themes for WordPress are vulnerable to Cross-Site Request Forgery in various versions. This is d… wordfence
1208ac78-4a56-4daa-b935-d579f07f8e8e
< 3.0.2
MEDIUM 5.3 The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… wordfence
12072b77-fe68-4304-8230-7c137a8d05ac
< 3.0.2
MEDIUM 5.3 wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, … wordfence
11f3c5bf-19cd-422a-a7f8-358669c78db5
< 1.1.1
MEDIUM 5.3 The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to unau… wordfence
11ecc255-cf8a-4fa9-a04a-d17946b1f167
< 2.3.2
MEDIUM 5.3 The Greek Multi Tool – Ultimate Greek Language Toolkit for WordPress plugin for WordPress is vulnerable to unauthorize… wordfence
11a61bef-da3b-46d6-8f78-0d4f9922f671
< 3.1.4
MEDIUM 5.3 The Events Made Easy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
11782a65-30b9-400e-8fe0-ab9f05ba5e42
< 4.2.11
MEDIUM 5.3 The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure… wordfence
1158081c-97da-4026-be16-994f4e41c92f
< 2.0.3
MEDIUM 5.3 The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to insuff… wordfence
114ff636-6b51-43a2-b2c8-19e01e94176f MEDIUM 5.3 The Vithy theme for WordPress is vulnerable to Sensitive Data Exposure in all versions via the index.php file. This can … wordfence
1128aca9-329d-4a3f-b0b0-36a4172524c5
< 1.1.0
MEDIUM 5.3 The GIFT4U – Gift Cards All in One for Woo plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
1114a84e-3425-402f-bcdc-a2ee05b2dbc9 MEDIUM 5.3 The KiotViet Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… wordfence
1101bfe6-2075-4f44-933b-6d9f372100a2 MEDIUM 5.3 The Pricing Deals for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data| due to a miss… wordfence
10e1b3ac-f002-4108-9682-5fe300f07adb
< 1.2.0
MEDIUM 5.3 The HT Easy GA4 – Google Analytics WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of… wordfence
10d7a50c-41e9-41b7-a171-d72dbe08e7b7
< 1.6.9.17
MEDIUM 5.3 The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitiv… wordfence
← Prev 1227 1228 1229 1230 1231 1232 1233 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top