πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 125 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ddf4ec13-bca3-4994-9e11-11fbbead371a
< 1.5.7
HIGH 8.8 Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin be… wordfence
ddd37b7a-3ef8-4269-ba3b-665ae34bde26
< 2.9.14
HIGH 8.8 The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
ddd06190-d0c1-445d-8c6f-4c7df3248db4
< 3.7.40
HIGH 8.8 WordPress Core is vulnerable to Cross-Site Request Forgery via wp-trackback.php in versions up to 6.0.3. This is due to … wordfence
ddb7b668-f023-427e-9ab5-90dc6d481028
< 3.3.24
HIGH 8.8 Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_… wordfence
dda2c437-8f41-480a-8816-2c07ab0eafa7
< 2.5
HIGH 8.8 The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es… wordfence
dd7a5a36-0e78-4fdc-b159-b4cc89cd3ffb
< 4.4
HIGH 8.8 The My Page Order plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting via t… wordfence
dd776106-2ec6-4813-946c-36e62a32d7df
< 11.12.6
HIGH 8.8 The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to arbitrary file uploads due to missing … wordfence
dd6df4fa-01b8-460f-b414-bb07fbc0436a HIGH 8.8 The slickquiz plugin through 1.3.7.1 for WordPress allows SQL Injection by Subscriber users, as demonstrated by a /wp-ad… wordfence
dd129829-9682-4def-a07f-66f9178eeb77
< 2.5.2
HIGH 8.8 The Droip plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the make_g… wordfence
dd1248b2-21ae-449e-acf8-3e5d6353f593
< 1.2.6
HIGH 8.8 Unrestricted File Upload vulnerability in Photo Gallery 1.2.5. wordfence
dd02becd-77e5-46b9-acc9-dba6c5caba27
< 2.2
HIGH 8.8 Several LWS Plugins for WordPress are vulnerable to authorization bypass due to making admin settings pages available to… wordfence
dd0054b5-537b-412f-8b10-8bbc9f2ea256 HIGH 8.8 The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with r… wordfence
dcddb0f3-41d5-4635-88ac-556ee3eec49a
< 0.3.12
HIGH 8.8 The Track The Click plugin for WordPress is vulnerable to time-based SQL Injection in versions up to, and including, 0.3… wordfence
dc9dcd42-bec1-4323-b5bf-6c0518ae546d
< 1.1.8
HIGH 8.8 The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF. wordfence
dc314c13-4be4-40fc-a035-5de0acb36c91
< 0.3.7
HIGH 8.8 The WP Simple Spreadsheet Fetcher for Google plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… wordfence
dc2d6986-fe9f-4776-b00f-35dd20687742 HIGH 8.8 The WPCHURCH - Church Management System for Wordpress plugin for WordPress is vulnerable to Privilege Escalation in all … wordfence
dc023c1b-7ec6-45b6-b50a-f0d823065843
< 2.4.41
HIGH 8.8 The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
dbf32808-b5d7-4f12-ada5-0578e0bef321
< 5.2.6
HIGH 8.8 Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (version… wordfence
dbee312d-a7a1-4a75-9847-a9c6a108e149 HIGH 8.8 The GitSync plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.0. Th… wordfence
dbd4a482-7176-446f-804d-e0cd0764a2cb
< 1.5.8
HIGH 8.8 The Store Toolkit for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and incl… wordfence
db70b37c-707a-47b8-a3a2-5a2b7d30de89
< 8.3.10
HIGH 8.8 The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
db6bb000-4f46-4a5a-b118-dcd3e78e4029 HIGH 8.8 The User Meta Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
db6616b5-4c4e-4cc7-83eb-22fac94f47f2
< 2.0.1
HIGH 8.8 The Themeflection Numbers plugin for WordPress is vulnerable to unauthorized data modification due to a missing capabili… wordfence
db4dbbbe-1edb-47a6-8d11-8a019e05dfae
< 1.6
HIGH 8.8 The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring… wordfence
db4616f7-e685-4dc7-947c-23c378a9bdd6
< 3.5.2
HIGH 8.8 The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem… wordfence
← Prev 122 123 124 125 126 127 128 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top