πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1238 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0578c49e-f820-42dd-bd53-f4a281843e69
< 1.25.11
MEDIUM 5.3 The Happyforms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in all versio… wordfence
0556738f-5c3c-4ff6-9432-d666328dc5e5 MEDIUM 5.3 The Post Grid plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin… wordfence
05529ca0-09f5-4047-9972-c0a2872ea857
< 1.4.3
MEDIUM 5.3 The Media File Manager plugin up to and including version 1.4.2 for WordPress allows directory listing via a ../ directo… wordfence
054bb123-132c-4c32-9fd1-a9f289cfdc35
< 1.2.2
MEDIUM 5.3 The Ad Blocking Detector Plugin plugin for WordPress is vulnerable to information exposure in all versions up to, and in… wordfence
0505d023-a5b9-4c86-aa9b-57ce2335f127
< 235
MEDIUM 5.3 The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to unauthorized modificati… wordfence
05056d99-ce19-4d41-844f-7757361fbe24
< 026.02.10.20
MEDIUM 5.3 The Cnvrse plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and excluding, … wordfence
0500c57a-3983-46e4-92fa-85f7fd47eba8
< 4.7.4
MEDIUM 5.3 The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin plugin for WordPress is vulnerable to Full Path … wordfence
04f0bffb-07bd-41f1-8e65-17ded38a8e2e
< 1.9.7
MEDIUM 5.3 The WP-LESS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1… wordfence
04eb82e4-1738-44c7-980e-8e33a7a3a23a
< 4.6
MEDIUM 5.3 The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to an… wordfence
04e0ddff-16af-4c85-b5b0-cf767684ee08
< 4.2.6.8.2
MEDIUM 5.3 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a mi… wordfence
049b7e92-c648-49e5-bab9-1b893d44faf9 MEDIUM 5.3 The Leadrebel plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
0490667e-4b82-4687-9354-205c37f13331
< 4.0.7
MEDIUM 5.3 The BestWebSoft Captcha plugin before 4.0.7 for WordPress allows remote attackers to bypass the CAPTCHA protection mecha… wordfence
048c37c2-0ace-4bf1-8cb8-554c4645be21
< 5.5
MEDIUM 5.3 The WPQA Builder WordPress plugin before 5.4 which is a companion to the Discy and Himer , lacks authentication in a RES… wordfence
048bc117-88df-44b3-a30c-692bad23050f
< 1.8.6
MEDIUM 5.3 The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i… wordfence
047c1519-4dc1-496c-b494-41ce1009e703
< 2.2.54
MEDIUM 5.3 The BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript… wordfence
0462df4d-1be5-4834-817a-8df0300d3188 MEDIUM 5.3 The Payment QR WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
041851d8-99ce-48a6-8ff5-85418d8807be
< 1.7.6
MEDIUM 5.3 The Document Embedder WordPress plugin before 1.7.6 contains a REST endpoint, which could allow unauthenticated users to… wordfence
0407223a-cd41-43d1-87b0-d6b83b57d4b3
< 2.3.7
MEDIUM 5.3 The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure … wordfence
04013d96-d1b2-4d97-ad10-c2739eb9bc30
< 4.0
MEDIUM 5.3 The WPLifeCycle plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
03f3d048-5099-406e-b386-31cbbbf4df14 MEDIUM 5.3 The Team 118GROUP Agent plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
03e96aea-30a2-4cd3-8967-52e1870cc293
< 2.3.0
MEDIUM 5.3 The WooCommerce Warranty Requests plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
03ccd474-42f4-4cbb-823e-93fe4db1bf80
< 9.5
MEDIUM 5.3 The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 d… wordfence
03b1d518-0e5d-4c28-af04-52611ad583a8
< 3.0.1
MEDIUM 5.3 The Product Filter by WBW plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
03aed95b-26a1-4903-b5aa-35abc889295d MEDIUM 5.3 The Share, Print and PDF Products for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
039ac1d9-ccb5-43d0-8b17-10d12b7df90e
< 1.8.1
MEDIUM 5.3 The Fluent Support plugin for WordPress is vulnerable to unauthorized email verification due to insufficient validation … wordfence
← Prev 1235 1236 1237 1238 1239 1240 1241 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top