ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1235 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0a28a161-3dbc-4ef0-a2ce-4c102cf3cbb0
< 2.11.0
MEDIUM 5.3 The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorizatio… wordfence
0a1fa859-e06c-4ce2-9325-e0be01882a88
< 10.1.0
MEDIUM 5.3 The The WP Recipe Maker plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to 10.1.0… wordfence
09fc03e4-0e83-4817-ab29-f45937c21f8e MEDIUM 5.3 The Popular Brand Icons – Simple Icons plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
09e158d2-f9a6-41a6-a91f-1763a1a44b04
< 1.1.1
MEDIUM 5.3 The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… wordfence
09dac668-fe4d-4119-a055-1a358fc4aacf
< 3.2.1
MEDIUM 5.3 The Survey Maker plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
09cbead3-1ab1-4b6b-a366-3160abb903a6
< 2.1.5
MEDIUM 5.3 The 百度站长SEOåˆé›†(支æŒç™¾åº¦/神马/Bing/å¤´æ¡æŽ¨é€) plugin for WordPress is vulnerable to unauthorized acce… wordfence
09c60d0a-bc1f-407f-aa0e-2ae0b7db5ae3 MEDIUM 5.3 The WP-FlyBox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.46. T… wordfence
09a1388e-6c87-44cd-a137-4212b569423b
< 2.13.0
MEDIUM 5.3 The Putler Connector for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mi… wordfence
09a01a43-5900-4dc6-a5f7-9d1529094ac0
< 5.4.31
MEDIUM 5.3 The Woffice Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
09980ab2-b67c-40ea-8920-8786aca80927
< 3.1.40
MEDIUM 5.3 The DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 3.1.3… wordfence
098dfee2-ba0b-420f-89ed-8ad1e41faec4
< 2.7.18
MEDIUM 5.3 The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data… wordfence
098c3f4c-b6bc-462a-98ef-30e6a68d74cf
< 1.5.7
MEDIUM 5.3 The Community Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
09588c2a-1631-4924-8277-d47f096493c5
< 5.6.3
MEDIUM 5.3 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Dir… wordfence
09406c75-d1ae-4baf-95a1-2c6a492dcf40
< 4.7.4
MEDIUM 5.3 The WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce plugin for WordPress is vulnerab… wordfence
09165fa9-75d2-43ec-8f71-1f43bf6ff7fd MEDIUM 5.3 The WooCommerce Payment Gateway for Saferpay plugin for WordPress is vulnerable to Path Traversal in all versions up to,… wordfence
0906e9b0-5093-4ddd-8868-8fcaad8e3a5b
< 2.3.13
MEDIUM 5.3 The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to unauthorized modification of data d… wordfence
09050c1e-26e0-46e7-b5f0-ebaff4066b0a
< 5.1
MEDIUM 5.3 The Optimize Database after Deleting Revisions plugin for WordPress is vulnerable to information disclosure in versions … wordfence
08fcba30-d28a-4e92-b7cd-ef1a4f37faf9
< 3.3.1
MEDIUM 5.3 The YayCurrency – WooCommerce Multi-Currency Switcher plugin for WordPress is vulnerable to unauthorized modification … wordfence
08f83fd1-5e8c-472f-819a-6078a5d2a56b
< 2.8.1
MEDIUM 5.3 The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password reque… wordfence
08f7800a-3c05-4654-b909-625c304d4129
< 2.2.1
MEDIUM 5.3 The Mailgun for WordPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 2.… wordfence
08dee232-7373-4da4-9c2c-c3aa52f9b588
< 4.1.0
MEDIUM 5.3 The Defender Security plugin for WordPress is vulnerable to protection bypass in versions up to, and including, 4.0.2. T… wordfence
08cb2162-fac3-47af-9292-116095ee40dc
< 6.9.4
MEDIUM 5.3 The WP SMS – Ultimate SMS & MMS Notifications, 2FA, OTP, and Integrations with WooCommerce, GravityForms, and More plu… wordfence
08beb583-096d-453c-9690-b46e410afb1b
< 1.9.2
MEDIUM 5.3 The Export Import Menus plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch… wordfence
08ab3d7d-b58a-4dec-a085-84a9938be328
< 3.5.2.5
MEDIUM 5.3 The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Insecure Direct Object Reference in all … wordfence
089ffe9a-e222-4630-b889-2b1e527dac6f
< 2.2.12
MEDIUM 5.3 The PayHere Payment Gateway plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … wordfence
← Prev 1232 1233 1234 1235 1236 1237 1238 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top