πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1234 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0bbbefce-4451-410d-bc19-f489318dda4a MEDIUM 5.3 The WP Clone Menu plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
0bba24d4-d906-4e00-a98f-25934e927641
< 6.3.7
MEDIUM 5.3 The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information … wordfence
0baaa6b7-3884-465e-bae3-46edab6312d4
< 1.5.7
MEDIUM 5.3 The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to expo… wordfence
0ba551a4-109d-4e28-b497-539264095134
< 5.2.13
MEDIUM 5.3 WordPress Core in various versions less than version 5.8.2 contained an expired DST Root CA X3 certificate. There is no … wordfence
0b9b6f5b-54e0-4603-abd7-394c7bd2af54
< 19.9.9.6
MEDIUM 5.3 The REHub Framework plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
0b8d337b-2d2c-4769-9ac0-6e22ba39a42f
< 2.26.5
MEDIUM 5.3 The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the… wordfence
0b85fc9c-f98d-44c5-8c5e-b9541c6c83b0
< 1.6.26
MEDIUM 5.3 The weForms – Easy Drag & Drop Contact Form Builder For WordPress plugin for WordPress is vulnerable to unauthorized a… wordfence
0b57a51f-7989-4e99-a339-70f831405696
< 8.5.2
MEDIUM 5.3 The Stripe Payment Forms by WP Full Pay plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
0b4cbe21-9f1b-425b-8141-ae075baaf717
< 5.9.11
MEDIUM 5.3 The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Auth… wordfence
0b48a35a-1110-4b63-bd7e-cc82350afa0e
< 11.1.1
MEDIUM 5.3 The Travel plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
0b45b352-4bc4-4338-9812-649541db4f4a
< 4.14
MEDIUM 5.3 The Gillion theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
0b328511-783e-447b-9c6b-2d54f165b59b MEDIUM 5.3 The Order Delivery & Pickup Location Date Time ( Free Version ) plugin for WordPress is vulnerable to unauthorized modif… wordfence
0b2e9103-16a8-4350-97ee-ae05a90850f6
< 5.4.10.4
MEDIUM 5.3 The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode… wordfence
0b2132db-761f-48ff-a737-115e07c77425
< 4.5.4
MEDIUM 5.3 The BizPrint plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the … wordfence
0b040a18-bd85-41c9-9add-65de79f5b79c
< 5.1.1
MEDIUM 5.3 The Shiptastic for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up… wordfence
0afc98b1-e1ee-4c77-89fc-9ccb045c6733
< 3.9.1
MEDIUM 5.3 The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized modification o… wordfence
0af9df66-8d82-4ae8-85a1-656d8ea40a7a
< 9.2.3
MEDIUM 5.3 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all … wordfence
0ae1cfe2-db79-46ba-bf10-0ee47f98e204
< 3.0.7
MEDIUM 5.3 The Contact Form to Any API plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and … wordfence
0a9bef24-ee99-4121-a4ea-ffd126b69b57 MEDIUM 5.3 The Wordapp plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
0a938042-bad6-4fe0-8905-148d07a22996
< 8.0.9
MEDIUM 5.3 The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable… wordfence
0a8453c4-effd-48fc-99c8-fc1f90cd23ea
< 4.3.7
MEDIUM 5.3 The LearnPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 4.3.6. This i… wordfence
0a809457-0a85-481a-b075-5239f656477c
< 2.7.20
MEDIUM 5.3 The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized ac… wordfence
0a79eb25-a7d1-4102-97e6-8fa8db9ed03e
< 3.4.19
MEDIUM 5.3 The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Discl… wordfence
0a49c8df-0524-41af-b095-b5953e6f68d8
< 5.6.2
MEDIUM 5.3 The iThemes Security plugin for WordPress is vulnerable to sensitive information disclosure in versions up to, and inclu… wordfence
0a2e647e-fb3b-4d5f-abb4-87923269c399
< 3.0.4
MEDIUM 5.3 The Quads Ads Manager for Google AdSense plugin for WordPress is vulnerable to Sensitive Information Exposure in all ver… wordfence
← Prev 1231 1232 1233 1234 1235 1236 1237 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top