πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1061 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
db5b5fa1-67b5-4103-93b0-682200199a71
< 6.5.0
MEDIUM 5.4 The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… wordfence
db15295f-505f-4a0a-bb3a-3ff6daf73008
< 2.3.2
MEDIUM 5.4 The Conditional Payments for WooCommerce plugin is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
dafbf6e2-1160-4551-a987-5e94c9157ff2
< 4.4.6
MEDIUM 5.4 The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Featu… wordfence
daa9abc2-310f-4bd9-9b88-d6f3024ab5f1 MEDIUM 5.4 The Psychological tests & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
daa48b64-6f89-40be-a31f-31d1481dfc91
< 3.0.3
MEDIUM 5.4 The Folders Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's First Name and Last Name … wordfence
da8af540-1623-42f2-a8af-4d3cadf1f5d0 MEDIUM 5.4 The Woocommerce Products Price Bulk Edit plugin for WordPress is vulnerable to Cross-Site Scripting via the wp-admin/adm… wordfence
da607df4-1dbb-4b1e-ace6-b339cf9e8512
< 3.4.6
MEDIUM 5.4 The WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on the wpcr… wordfence
da3070aa-fae8-465a-95e5-ae92dcd89f66
< 0.4
MEDIUM 5.4 There is a Cross-Site Scripting vulnerability in Microsoft Clarity version 0.3. The XSS payload executes whenever the us… wordfence
d9b10db9-0c7c-4f13-9d98-6d407446cfb8
< 5.0.4
MEDIUM 5.4 The The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to arbitrar… wordfence
d970a9f6-69f6-42d2-b863-82b8110e52c3
< 3.4
MEDIUM 5.4 The Taggbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknown fu… wordfence
d9545264-0434-4976-b94e-4e520e5ae9c6
< 1.9.41
MEDIUM 5.4 The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginn… wordfence
d94f6cdd-8232-4e0c-b510-0e755c280b58
< 6.6.0
MEDIUM 5.4 The Site Reviews plugin for WordPress is vulnerable to setting modification and information disclosure due to lack of ca… wordfence
d93c70d6-c439-4bcd-a855-b71896bf9d22
< 2.8
MEDIUM 5.4 The Prismatic WordPress plugin before 2.8 does not sanitise or validate some of its shortcode parameters, allowing users… wordfence
d92bfa61-7ae2-427a-8f3a-82709471735b
< 2.5.1
MEDIUM 5.4 The WP Discord Invite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 2.5.1. This is … wordfence
d8fab229-cd6b-45a3-9e80-a03a1704ad3e
< 2.7.8.1
MEDIUM 5.4 The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to unauthorized access … wordfence
d8cb9488-a73e-4e27-8927-3e6ac65b33c5 MEDIUM 5.4 The Website Chat Button: Kommo integration plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
d8c1823c-72be-4342-b4e9-0dc18afbb4a8
< 6.3.2
MEDIUM 5.4 The Advanced Custom Fields Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
d8a12e1d-f46a-499e-bfd6-185d5b955071
< 6.10.23
MEDIUM 5.4 The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Insufficient Access Control on Multiple AJAX Act… wordfence
d888cd53-415c-4667-b35a-5b3bd2226eeb
< 1.0.1
MEDIUM 5.4 The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow u… wordfence
d875514c-c7d3-4236-842b-6e772048448d
< 4.0.1
MEDIUM 5.4 The Post Type Switcher plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inc… wordfence
d80199a2-8a12-44f7-ba20-169d7af88c26
< 2.18.1
MEDIUM 5.4 The Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to unauthorized … wordfence
d7f2b39f-d2e1-459d-b02d-6d064c471ed2 MEDIUM 5.4 The Ongkoskirim.id plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
d7c639b8-35f5-4eaf-a663-1adab3ba2a16
< 3.5.6
MEDIUM 5.4 The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cro… wordfence
d7911337-57fa-4268-8366-d37ff13fae86 MEDIUM 5.4 The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
d703abc2-3269-42b2-a75c-d163df62260d
< 6.5
MEDIUM 5.4 Jetpack up to 6.4.2 is vulnerable to stored Cross-Site Scripting. This allows attackers with contributor privileges to i… wordfence
← Prev 1058 1059 1060 1061 1062 1063 1064 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top