πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1237 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
070d7310-ae5f-4486-9b93-36253e24f895
< 2.0.19.13
MEDIUM 5.3 The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all v… wordfence
07069f39-f892-4c19-8e0b-e5e17b1ffb21
< 2.7.7
MEDIUM 5.3 The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Di… wordfence
06f0d53d-734c-4cc1-902d-bdf4826036bf MEDIUM 5.3 The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.… wordfence
06ef9a21-e2b9-40c7-9de5-cff175fa10a5
< 6.5.6
MEDIUM 5.3 The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions … wordfence
06d58e94-225e-43ca-823b-60d921a2dd8d MEDIUM 5.3 The ShopWP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
06c3de6d-92e7-46f8-86a9-37f027767fc0
< 6.4.15
MEDIUM 5.3 The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure … wordfence
06b290c2-e458-46da-abed-0ab5d63d1550
< 2.3.0
MEDIUM 5.3 The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin f… wordfence
0696b9e2-3685-4bea-8b1f-74e2dc927532 MEDIUM 5.3 The SiteAlert (Formerly WP Health) plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca… wordfence
067b70a5-ad1a-446f-832f-cbf3088d2f59
< 1.0.32
MEDIUM 5.3 The Sendcloud Shipping plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
06738434-ccd4-4e87-8163-d56ff3b4b5c8
< 3.1.18
MEDIUM 5.3 The WordPress Download Manager plugin for WordPress is vulnerable to unauthorized download duplication in versions up to… wordfence
06662ba5-1d27-4b44-8f5a-947e1392f688 MEDIUM 5.3 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to unauthorized access due to a miss… wordfence
0655cd61-8ebe-47f8-a21b-6311c98a7193
< 7.9.0
MEDIUM 5.3 The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable … wordfence
0646fcba-afe5-49a2-acd5-e15d009926c4
< 1.0.2.4
MEDIUM 5.3 The Send PDF for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of form submissions due to a m… wordfence
063b50e3-1369-4240-b695-6ac336f4ea75
< 6.5.6
MEDIUM 5.3 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unaut… wordfence
0633bf06-6580-4feb-b98a-c465df3e2bed
< 6.0.7.0
MEDIUM 5.3 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … wordfence
061a14bf-d067-4924-b2f4-2f5986204532
< 2.2.2
MEDIUM 5.3 The SureForms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
0612c0be-f1c0-4f74-a769-e4616f103ee6 MEDIUM 5.3 The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to Missing Authorization in al… wordfence
0608fb1c-0c01-40b6-9506-2e2336523df2
< 2.3.1
MEDIUM 5.3 The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to unauthorized acce… wordfence
05fe7d6d-c206-4444-aab2-e4f64b143710
< 5.0.5
MEDIUM 5.3 The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
05fae1f8-0546-4505-8749-a9deea237d10 MEDIUM 5.3 The iGMS Direct Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
05eeb878-e5f4-4cdb-b106-baea66b71f10
< 8.6.1
MEDIUM 5.3 The Directorist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
05e8ec0d-74ad-483a-914d-f40c0cfc9b24
< 7.6.10
MEDIUM 5.3 The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Password Protection Bypass in all versions u… wordfence
05dbfd37-38bc-44e8-9ba9-81baca7bb6d0
< 1.4.0
MEDIUM 5.3 The Travel Booking theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
059ede2b-c163-464f-bf85-bb5ec5e6c620
< 1.4.7
MEDIUM 5.3 The Hybrid Composer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
05909e9c-4f57-4556-bae9-b0b63a9a43ba
< 1.1.0
MEDIUM 5.3 The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1… wordfence
← Prev 1234 1235 1236 1237 1238 1239 1240 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top