πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1060 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e087817e-9edb-4c93-96c6-e8d8e99d4d9b MEDIUM 5.4 The WP All Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4… wordfence
e033dd4a-bc82-403a-82aa-cd8516290f4a
< 1.2.1
MEDIUM 5.4 The Export Post Info plugin for WordPress is vulnerable to CSV Injection. This allows authenticated users with author pe… wordfence
dfa2af3d-ef5a-484b-83a3-552b03b16f4b MEDIUM 5.4 The BxSlider WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions u… wordfence
df9b0578-d5fb-459b-b857-d907e4ca22b4
< 1.1.7
MEDIUM 5.4 Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outp… wordfence
df6e5aee-e79d-4c3f-a0c4-47436ae7c1da
< 2.9.1
MEDIUM 5.4 The Premium Addons PRO plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capabili… wordfence
debe6f54-0f56-4bc9-a0cd-4f2caa1ed9e3 MEDIUM 5.4 The Newsmag theme for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to,… wordfence
dea1e775-68b4-45e6-9d90-41e39d5d0dfd
< 1.3.5
MEDIUM 5.4 The Gravity Forms Google Sheet Connector plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
de9a945b-31fb-4d0d-9dd1-23bcef1399c2
< 1.3.0
MEDIUM 5.4 The Show-Hide / Collapse-Expand plugin for WordPress is vulnerable to authorization bypass due to a missing capability c… wordfence
de91c6f1-12b6-4759-90b0-507c9736b3d4
< 30.1
MEDIUM 5.4 The WooCommerce Customers Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
de614bbd-42ae-4c2a-aec6-31245124de76
< 4.5.4
MEDIUM 5.4 The Essential Addons for Elementor Lite WordPress Plugin before 4.5.4 has two widgets that are vulnerable to stored Cros… wordfence
de5397c2-b23c-412a-b419-e36023daa989 MEDIUM 5.4 The DNUI plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.1. This … wordfence
de4ba999-3312-4bcc-ab87-574b7994e07e MEDIUM 5.4 The RingCentral Communications Plugin – FREE plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… wordfence
de3a6e77-47ee-4989-81a0-5447a73185bb MEDIUM 5.4 The Activity Reactions For Buddypress plugin for WordPress is vulnerable to missing authorization checks in versions up … wordfence
de1742d4-f498-4ad4-b6a1-88cb60e83afc
< 3.20.2
MEDIUM 5.4 The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pos… wordfence
ddf67d69-f362-4380-a396-300c7edbd9f3
< 4.7.70
MEDIUM 5.4 The Download Monitor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includi… wordfence
ddd1ccda-e96a-4dd7-a68f-b42c40619bf6
< 4.48
MEDIUM 5.4 The Car Dealer plugin for WordPress is vulnerable to unauthorized access to data due to a missing capability check on th… wordfence
dd9e6ba7-f107-4d7c-a7da-35e603f3a1a8
< 3.3.13
MEDIUM 5.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versi… wordfence
dd56cb73-1c40-44b1-b713-c0291832d988 MEDIUM 5.4 The Page Builder by AZEXO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
dcd59ae6-4e5a-4efb-9abb-43c482e41b16 MEDIUM 5.4 The BNS Twitter Follow Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, a… wordfence
dcd05142-9700-46a8-9ca6-f85e81dfee0d
< 1.6.8
MEDIUM 5.4 The Short URL plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data … wordfence
dc01108f-e781-484b-997a-c1d4e218a3f4
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
dba0a90b-f13c-4914-b6b7-278227ffc122
< 3.9.15
MEDIUM 5.4 The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod… wordfence
db952443-2588-4da0-87d8-5bd2d3be039c
< 2.5.2
MEDIUM 5.4 The ShopLentor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.1.… wordfence
db7903ef-f4e5-452b-b88a-a3933ced833f
< 1.2.5
MEDIUM 5.4 The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field f… wordfence
db6bec6c-77d1-4dab-9893-cf33a2fac629
< 6.2.6
MEDIUM 5.4 The Photo Engine plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including… wordfence
← Prev 1057 1058 1059 1060 1061 1062 1063 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top