πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1239 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
037ac32a-dc2e-4e9f-9318-65dfee1c80e9 MEDIUM 5.3 The AA Block Country plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1. … wordfence
03774303-c9f4-4666-ac88-78f92aaf81dc MEDIUM 5.3 The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing c… wordfence
0360c5d9-5534-4f6c-9b54-61c09a5d76f5 MEDIUM 5.3 The ListingPro Lead Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
035f2be6-6c20-4f61-8302-bf36df633c80
< 1.1.5
MEDIUM 5.3 The COMPE – WooCommerce Compare Products plugin for WordPress is vulnerable to Insecure Direct Object Reference in all… wordfence
034246b2-e123-480d-afaf-cce9d42f1f03
< 1.4.9
MEDIUM 5.3 The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaint… wordfence
0323b54b-c15b-4d2d-9e8f-3df87c84dd49
< 4.5.13
MEDIUM 5.3 The WP Meta SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… wordfence
031df7ea-b341-40fc-981f-711883f08742
< 1.18.1
MEDIUM 5.3 The Pochipp plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
0312cea9-8205-4d09-874d-aef319d15c65
< 2.3.9
MEDIUM 5.3 The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnera… wordfence
030bb667-b8e6-4987-8af2-83cfa4bed8a6 MEDIUM 5.3 The EPROLO-Dropshipping plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, … wordfence
02f4987d-575f-4ee7-a3b7-c76a16cf1fe2
< 2.24.0
MEDIUM 5.3 The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Refere… wordfence
02d994b7-2891-47d0-92d3-c33c4eac54f0
< 2.1.2
MEDIUM 5.3 The SharkDropship and Affiliate for AliExpress, eBay, Amazon, Etsy plugin for WordPress is vulnerable to unauthorized lo… wordfence
02d61a68-0bcf-4a6d-8e19-c1546b9e59d9
< 1.11.4
MEDIUM 5.3 The Cooked plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
02c5e3ad-5cc3-40b1-a15a-10d53383abe6
< 20260217
MEDIUM 5.3 The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Incor… wordfence
02b0d7d7-8a10-48de-b1e1-7e1f1fda6ffe
< 4.3.2
MEDIUM 5.3 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Infor… wordfence
02af9eab-fe69-4adb-b6e8-bf710b00af3f MEDIUM 5.3 The Book Previewer for Woocommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
029b4554-518e-484e-9e3a-7275a5fe1f17
< 4.11.3
MEDIUM 5.3 The udesign theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
02461b79-d372-493f-9445-62b30b1db4cd
< 4.2.7.0
MEDIUM 5.3 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access due t… wordfence
023bef79-a3ab-41f7-a287-955c6331c77e
< 3.10.3
MEDIUM 5.3 The Posti Shipping plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.10… wordfence
0232a3a5-e91e-4213-8c21-900fc805bad7
< 1.4.6
MEDIUM 5.3 The Contact Builder by Themify plugin is vulnerable to email injection in versions up to, and including 1.4.5. This make… wordfence
0227e5f0-61fa-4e78-9bd4-918fdde7ab58
< 1.6.3
MEDIUM 5.3 The WordPress Leads plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on mult… wordfence
02220c1d-a7f2-41eb-ac5f-f89d63c54a59
< 4.7.1
MEDIUM 5.3 The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Sensitiv… wordfence
021a25c9-7fad-425f-8104-bb4852603613
< 7.6.1
MEDIUM 5.3 The WordPress Social Login and Register plugin for WordPress is vulnerable to Missing Authorization in versions up to, a… wordfence
0213cfce-6dee-4607-bc0f-2001fc208725 MEDIUM 5.3 The Featured Video Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and incl… wordfence
0210ee40-543a-42ce-b7da-e5bbae19d852
< 2.0.0
MEDIUM 5.3 The Heureka plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
020da86b-63d6-4687-bf2d-ab10fe19e9ce
< 2.0.46
MEDIUM 5.3 The User Verification by PickPlugins plugin for WordPress is vulnerable to unauthorized access due to a missing capabili… wordfence
← Prev 1236 1237 1238 1239 1240 1241 1242 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top