πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1456 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
88db8ee1-4c13-41e6-9dce-04cd9fa8ca70
< 1.5.3
MEDIUM 4.3 The CM Search And Replace – Optimize content edits with a powerful search and replace tool plugin for WordPress is vul… wordfence
88db56a6-8e4c-4ef8-b51a-a2744c3132e2
< 7.2.8
MEDIUM 4.3 The File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… wordfence
88db1993-f13a-4ddd-b410-47a2bf08ee3f
< 2.16.4
MEDIUM 4.3 The Melhor Envio plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
88dab094-aaa0-4287-bbb0-2101a6c970cc
< 1.0.8
MEDIUM 4.3 The Conformer for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
88ca14d5-bbdd-4efa-a729-40a73f701aae
< 3.0
MEDIUM 4.3 The Button Generator – easily Button Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… wordfence
88c85270-d464-4f20-84e5-80f63e7c73e2
< 2.0.3
MEDIUM 4.3 The New Order Notification for Woocommerce plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
88c771a9-e908-451b-bbc4-c10634d9c36b MEDIUM 4.3 The AutoWP – AI Content Writer & Rewriter plugin for WordPress is vulnerable to unauthorized access due to a missing c… wordfence
88bba345-5330-4780-8c76-fd0f72fb4048 MEDIUM 4.3 The KK I Like It plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
88b4791e-8c48-446e-b713-8958d60f668f
< 2.0.1
MEDIUM 4.3 The HashBar – Announcement, Notification Bar & Popup Campaign plugin for WordPress is vulnerable to Cross-Site Request… wordfence
88aef7e0-ffa4-4090-a6e9-295023c71c6c
< 1.6.5
MEDIUM 4.3 The Dynamic Widgets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
889ec0f7-22e3-48b9-9571-d0c399b9d5c2 MEDIUM 4.3 The WooCommerce Orders & Customers Exporter plugin for WordPress is vulnerable to Sensitive Information Exposure in all … wordfence
8896fa5a-1642-4fcd-8fff-1e5828c28523
< 1.6.1
MEDIUM 4.3 The QR code MeCard/vCard generator plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… wordfence
8883d4fe-3ca6-4591-9972-219b114126d3
< 5.4.1
MEDIUM 4.3 The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da… wordfence
887ecedb-0bc8-4488-b6fa-27cfa22345e6 MEDIUM 4.3 The WPCargo Track & Trace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … wordfence
885ecd04-53f0-4f61-a38f-1bb467960ad7
< 1.2.14
MEDIUM 4.3 The Premmerce Brands for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
8856f3db-a5e5-4f7a-8527-8e0a9616feb1
< 1.2.3
MEDIUM 4.3 The Exchange Rates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
881e8096-e75f-49a7-87ed-c230e93ea378
< 5.47.0
MEDIUM 4.3 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing … wordfence
880e5752-cc69-4c38-bd00-a3b8517e5fa6 MEDIUM 4.3 The Filter Custom Fields & Taxonomies Light plugin for WordPress is vulnerable to unauthorized access due to a missing c… wordfence
88089d8e-9040-482d-b0e5-d2412885f390
< 10.30.20
MEDIUM 4.3 The Salon Booking System plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1… wordfence
880712ee-373f-49e7-93e3-968f3a0f3f83 MEDIUM 4.3 The Simple Theme Changer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
88002a25-6890-4f8b-8a11-239b59d56672 MEDIUM 4.3 The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and… wordfence
87f9f052-2963-4548-9ff8-91dc2b4ecb43
< 2.4.5
MEDIUM 4.3 The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized modification of d… wordfence
87f82d5d-d89a-440d-8c23-ace5160a0739
< 4.1.9
MEDIUM 4.3 The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to… wordfence
87f52e3a-e414-4f47-b46c-e3811e76744b
< 5.0.7
MEDIUM 4.3 The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch… wordfence
87eafa6c-459e-49e3-b4c9-2be48c5dfc78
< 1.6.1
MEDIUM 4.3 The Solace Extra plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
← Prev 1453 1454 1455 1456 1457 1458 1459 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top