πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1499 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5ab989ea-f498-4c74-b761-416d73059108
< 2.3.1
MEDIUM 4.3 The Image Source Control WordPress plugin before 2.3.1 allows users with a role as low as Contributor to change arbitrar… wordfence
5ab508fa-298c-48c1-8510-f2e0a881675a MEDIUM 4.3 The ACF to REST API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and in… wordfence
5aaa178d-f942-4f41-bd8e-5b3bff8aca6c MEDIUM 4.3 The 1003 Mortgage Application plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
5a9b284a-2af9-4d20-9663-a40b9330da35 MEDIUM 4.3 The Comparison Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
5a9943b5-0f6d-4fbd-97eb-df61acd0c297
< 2.3.21
MEDIUM 4.3 The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.… wordfence
5a9665e5-5aea-491b-a5e7-29723347aaad
< 1.23.10
MEDIUM 4.3 The MeetingHub for Zoom Meeting, Google Meet, Jitsi Meet, Webex, & Microsoft Teams | The All-in-One Webinar & Video Conf… wordfence
5a94c5e7-a3d6-435b-9d10-0c325a13124f
< 6.1.2
MEDIUM 4.3 The Awesome Support plugin for WordPress is vulnerable to Insecure Direct Object Reference to (Subscriber+) Ticket Expor… wordfence
5a88a6fd-cd49-46c4-8b8e-dd8499d3208c
< 6.9.1
MEDIUM 4.3 The Bit File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includi… wordfence
5a85c367-99f5-4a46-94bc-ed6e6626514b
< 6.1.15
MEDIUM 4.3 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vul… wordfence
5a7bb428-dd65-47f7-aaf6-ecdad4ae3049
< 1.7.7
MEDIUM 4.3 The Simple Post Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 1.7.7 (excl… wordfence
5a628eef-937c-4391-afac-22128ec5b51c
< 1.3.9
MEDIUM 4.3 The Better Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… wordfence
5a5d3a62-f7e5-4776-bed9-7ff3f81da452
< 1.1.11
MEDIUM 4.3 The Replace Image plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl… wordfence
5a58f809-d051-4841-a1da-7bc1cf59e1a2 MEDIUM 4.3 The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… wordfence
5a580a7a-d477-47ba-a7c1-21d7312c53ba
< 1.4.1
MEDIUM 4.3 The MAZ Loader WordPress plugin before 1.4.1 does not enforce nonce checks, which allows attackers to make administrator… wordfence
5a56e621-2508-4500-b865-4d5e4463b91a
< 5.7.18
MEDIUM 4.3 The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin… wordfence
5a4833de-d530-4bbf-ac28-e5d4b5f68f1e MEDIUM 4.3 The Coding Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
5a2b7aac-b11d-4c52-b3d8-7b3f4b3eecd5 MEDIUM 4.3 The Open Graph Metabox plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
5a20d2fb-c022-4a34-9379-8dd31fda102c
< 3.3.0
MEDIUM 4.3 The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to unauthorized access due to a mi… wordfence
5a0aded4-b891-47d9-950e-180103b90a1c
< 14.2.1
MEDIUM 4.3 The Latest Post Shortcode plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
59ff3445-0dfd-4a1a-9ac8-d088b8f4dbf3
< 4.1.6
MEDIUM 4.3 The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due… wordfence
59edf88d-a16d-48ec-981a-0002730f4091
< 4.11.64
MEDIUM 4.3 The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauth… wordfence
59d14f6c-6286-454c-8629-96a0c2de943c
< 2.0.5
MEDIUM 4.3 The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to Insecure Direct… wordfence
59a63cd8-9d33-4a2c-a499-5b1ee38c07d6
< 4.1.4
MEDIUM 4.3 The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vu… wordfence
59a5b35c-8910-401f-9829-e9257e3f231d MEDIUM 4.3 The Quick Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
5981209b-5dc7-4823-bd90-2f9514beb616
< 6.0.1
MEDIUM 4.3 The Announcer – Notification & message bars plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
← Prev 1496 1497 1498 1499 1500 1501 1502 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top