๐Ÿ›ก๏ธ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1120 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
de043a2e-6eb0-4eb4-8c20-4efd3fa965d8
< 2.1.5
MEDIUM 5.3 The Razorpay Payment Links for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
ddfa5a3d-fef2-4049-915c-51c3e28153bf
< 9.1.9
MEDIUM 5.3 The NEX-Forms โ€“ Ultimate Forms Plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa… wordfence
ddf9a043-5eb6-46fd-88c2-0f5a04f73fc9
< 4.10.1
MEDIUM 5.3 The GiveWP โ€“ Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification … wordfence
ddb2290d-d4bd-4f70-9fe9-927f49721811
< 6.8.2
MEDIUM 5.3 The Advanced Custom Fields (ACFยฎ) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and… wordfence
dd77f939-cd1c-4624-9a0c-d8f89a8e5221
< 2.1.5
MEDIUM 5.3 The weDocs plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on … wordfence
dd35a017-3b80-483d-8144-3986ea064669 MEDIUM 5.3 The WC Plus plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
dd340ecc-d698-43e1-a15c-479088fb8cf4
< 5.0
MEDIUM 5.3 The Easy Accept Payments via PayPal plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
dd22276b-41d4-4795-a79e-d770d0cf4b76
< 1.3.6
MEDIUM 5.3 The WPGraphQL plugin for WordPress is vulnerable to Denial of Service via field duplication in versions up to, and inclu… wordfence
dd090b6b-e428-4bfa-b3d0-9fb6de92cf9d
< 1.4
MEDIUM 5.3 The Easy PayPal Events & Tickets plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up t… wordfence
dd072774-6f85-42de-a9d4-6826703ad839
< 1.0.271.1
MEDIUM 5.3 The Rank Math SEO โ€“ AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access du… wordfence
dcfead67-d75d-46ae-ac68-a34643ac2f52
< 4.4.9
MEDIUM 5.3 The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … wordfence
dcd24b90-94ff-4625-8e3e-9c90e38683f9
< 3.30.7.1
MEDIUM 5.3 The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7 … wordfence
dccc2710-fdaf-40d6-ab07-51f3e8c2f382 MEDIUM 5.3 The Reuters Direct plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
dcbb6a4c-120f-43d1-8ec9-dac52186d81a
< 6.1.15
MEDIUM 5.3 The Simple File List plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1… wordfence
dcb33d02-d384-4dff-91e1-c49e86b97d6e
< 2.2.1
MEDIUM 5.3 The Flynax Bridge plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on t… wordfence
dca7b232-db12-48a7-9f32-4451f4ced1af
< 20.8.9
MEDIUM 5.3 The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
dca56345-0ac6-4e1a-9832-8ba428667913 MEDIUM 5.3 The Top Bar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
dc9602fb-59d0-43bb-aa13-adfc2319db8e
< 3.6.26
MEDIUM 5.3 The DirectoryPress โ€“ Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to unauthorized a… wordfence
dc72d99b-f29b-4ac4-8228-eea2837ab457 MEDIUM 5.3 The JS Job Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
dc7211fc-2c16-4080-a0b6-2090e1e4601c
< 2.0.23
MEDIUM 5.3 The Distance Based Shipping Calculator plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
dc428f4b-fe82-419a-aee3-38f0bb582506
< 5.8.1
MEDIUM 5.3 The WooCommerce Predictive Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
dc36ee53-81a9-416e-8e74-31d9c8802d6c
< 8.5.7
MEDIUM 5.3 The WPBot โ€“ AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizat… wordfence
dc319d4e-06d5-4fba-9f7a-2eb8c2e089f4
< 4.0.16
MEDIUM 5.3 The WhyDonate โ€“ FREE Donate button โ€“ Crowdfunding โ€“ Fundraising plugin for WordPress is vulnerable to unauthorized… wordfence
dc18a5c4-6e63-4ad1-a90e-8337b5a86c48
< 1.3.2
MEDIUM 5.3 The Download Attachments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a… wordfence
dbf0f614-e5e9-486c-a0dd-cd494708a2a8 MEDIUM 5.3 The WP Repost plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
← Prev 1117 1118 1119 1120 1121 1122 1123 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top