πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1062 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d6f20fc3-41e5-4220-ac8b-54eb11719f07
< 1.8
MEDIUM 5.4 The Freshdesk (official) Plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.7. This… wordfence
d6a51962-fe99-4911-85c9-a75bd18e74c2
< 3.7.31
MEDIUM 5.4 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled durin… wordfence
d66665b6-8cb2-4bc0-929d-4a8689bada9e
< 3.0.3
MEDIUM 5.4 The WooSwipe WooCommerce Gallery plugin for WordPress is vulnerable to authorization bypass due to a missing capability … wordfence
d62d0971-c4bc-40f7-80b4-a3d54ce4f3ac
< 2021.08.10
MEDIUM 5.4 The Daily Prayer Time WordPress plugin before 2021.08.10 does not sanitise or escape some of its settings before outputt… wordfence
d60f3da1-1184-4629-880c-ce3893fb55a5
< 5.36.1
MEDIUM 5.4 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data and modification … wordfence
d608a4c0-14ba-4801-aa5a-0b4dab0acd65
< 2.0.2
MEDIUM 5.4 The PDF.js Viewer WordPress plugin before 2.0.2 does not escape some of its shortcode and Gutenberg Block attributes, wh… wordfence
d5d12ecc-862f-4ecd-9c7b-25dc557abb8d MEDIUM 5.4 The ARforms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in… wordfence
d5a6e9f4-dbc3-4af0-b9e4-4c9ad7b5fe9f
< 5.1.5
MEDIUM 5.4 The Filebird plugin for WordPress is vulnerable to unauthorized SPI key generation due to a missing capability check on … wordfence
d57b8c89-109c-4b3b-bea4-adfe7dbfb26d MEDIUM 5.4 The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, … wordfence
d5688bb7-cd2d-42c6-b8cf-d908448ccfc1 MEDIUM 5.4 The Order Your Posts Manually plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'cat_id' para… wordfence
d55c832b-f558-4e8a-8301-33dd38d39ef1
< 1.15.22
MEDIUM 5.4 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross… wordfence
d47f5d90-dc7d-4500-a6e6-e585e4a5c11b MEDIUM 5.4 The Change WooCommerce Add To Cart Button Text plugin for WordPress is vulnerable to unauthorized modification of data d… wordfence
d46d6493-8b89-4258-9d83-79e5946cd76f
< 1.0.5
MEDIUM 5.4 The My Social Feeds – Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in al… wordfence
d40d6228-dacd-4f94-b6a3-a402c4e24554
< 2.1.2
MEDIUM 5.4 The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a mi… wordfence
d3beee75-0480-4504-a177-45f8cd32cf36
< 0.6.2.9
MEDIUM 5.4 The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
d31b9022-ae45-4bc2-b820-fb88faf0796f MEDIUM 5.4 The IMPress Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple listing fields in ve… wordfence
d2d34c84-473c-49f8-b55c-c869b5479974
< 1.3.3
MEDIUM 5.4 The Grid Plus plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing … wordfence
d2594cef-6bde-425f-9412-fd4ed3da312e
< 1.6.0
MEDIUM 5.4 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
d1e38cdc-7bc5-4963-9ebe-efd6c6ea228d
< 1.1.7
MEDIUM 5.4 The Easy Media Download WordPress plugin before 1.1.7 does not escape the text argument of its shortcode, which could al… wordfence
d1c43e93-69a3-407e-860e-ab25af5d7177
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… wordfence
d14c8890-482c-4d43-a68f-0d04c4feca8f
< 1.7.9
MEDIUM 5.4 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
d0dcf95e-1540-48ed-a4a2-f803d67ea141
< 5.0.6
MEDIUM 5.4 The Multi Rating for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.0.5. This… wordfence
d0ca9780-8918-40ff-80c0-62ce483adbae
< 7.3.0
MEDIUM 5.4 The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This … wordfence
d0c724a4-7783-4d2a-938e-800960c2be64 MEDIUM 5.4 The Pet Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, … wordfence
d0631ac6-2d85-4073-be2c-05480deecf97
< 1.6.0
MEDIUM 5.4 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
← Prev 1059 1060 1061 1062 1063 1064 1065 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top