πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1240 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0201d430-1254-4b09-b7a0-1443861ddf42
< 5.3.9
MEDIUM 5.3 The WooCommerce Multilingual & Multicurrency with WPML plugin for WordPress is vulnerable to unauthorized access due to … wordfence
01d040c8-5fd9-4dc7-af30-10c58571b16f
< 1.2.7
MEDIUM 5.3 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to unauthorized access in… wordfence
019cfdff-c67b-4451-984d-a7b6973ab61d
< 1.0.3
MEDIUM 5.3 The Blogpoet theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
0195f3db-cf36-40ab-a818-9c00a269f065 MEDIUM 5.3 The Shown Connector plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
018fafb9-0e86-47b2-b747-04aab1c1d5e0 MEDIUM 5.3 The Wava Payment plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
017fe804-a1a5-4f8d-a531-e928d668dbc4
< 8.6.01.005
MEDIUM 5.3 The WP Photo Album Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 8.5.… wordfence
0173e2a3-452d-490b-8ed7-a049a476d137
< 1.7.4
MEDIUM 5.3 The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Insecure D… wordfence
01707346-86c2-45c8-a2c9-81a147506fa4
< 2.1
MEDIUM 5.3 The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including… wordfence
015942ef-fb6c-4b58-ab67-f7e903321f32
< 3.5.35
MEDIUM 5.3 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
013ff32d-b3ea-4d36-87c3-a31de447e699 MEDIUM 5.3 The BizReview plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
013f7c26-8348-4c54-af61-473a720a5095
< 5.5.7
MEDIUM 5.3 The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions … wordfence
012b5334-afdc-47bd-8eaf-967b40fef59b
< 2.8.1
MEDIUM 5.3 The Popup Anything – Popup for opt-ins and Lead Generation Conversions plugin for WordPress is vulnerable to unauthori… wordfence
01299aba-0dff-47fd-9e90-ee84f00a0f3b
< 1.3.0
MEDIUM 5.3 The Guest Support plugin for WordPress is vulnerable to User Email Disclosure in versions up to, and including, 1.2.3. T… wordfence
010590bc-98fb-4afe-9c5e-80ad4c50a34e
< 1.4.8
MEDIUM 5.3 The Hash Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on… wordfence
00ff9034-d890-4d56-8f07-d66672e79983
< 11.1.3
MEDIUM 5.3 The Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker plugin for WordPress is vulnerable to User Enumeration in… wordfence
00ec7251-3be1-411a-b38e-1782d1691e18
< 1.3.8.6
MEDIUM 5.3 The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file d… wordfence
00ba5eae-668a-4452-9562-9f49b730daaa MEDIUM 5.3 The Contact Form Builder, Contact Widget plugin for WordPress is vulnerable to protection bypass in all versions up to, … wordfence
00b81467-8d00-4816-895a-89d67c541c17
< 4.2.6.3
MEDIUM 5.3 The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure… wordfence
00a33386-c401-4942-9dca-82555d2e87c6 MEDIUM 5.3 The NOWPayments for WooCommerce – Crypto Payment Gateway plugin for WordPress is vulnerable to unauthorized access due… wordfence
0088a97c-5a06-4500-a923-242499596aca
< 4.10.1
MEDIUM 5.3 The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and incl… wordfence
0064244b-72a4-486d-aaad-be1f57e4a8a1
< 2.5
MEDIUM 5.3 The Add Admin CSS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1… wordfence
0049583a-0ad3-45e4-a29e-4b8c33d09857
< 4.3.8
MEDIUM 5.3 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP… wordfence
003694f8-23be-4c94-899d-76b9b8488202
< 5.4.6
MEDIUM 5.3 The kk Star Ratings plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 5.4.5. … wordfence
00130f32-36eb-4a76-bac5-b6407edf1c48
< 4.3.1
MEDIUM 5.3 The WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets plugin for WordPress is vulnerable to Sensitive … wordfence
21c09207-38a1-47ae-ae1e-52f8eea4785d
< 2.5.8
MEDIUM 5.2 The AWeber Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add… wordfence
← Prev 1237 1238 1239 1240 1241 1242 1243 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top