🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 126 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
db251792-cbad-41e1-aaca-4cd39a25b444
< 3.32.1
HIGH 8.8 The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
dae2d028-6976-468a-9e93-ec712887d657
< 10.5
HIGH 8.8 The LionScripts: IP Blocker Lite plugin for WordPress is vulnerable to arbitrary file uploads via Cross-Site Request For… wordfence
dad288b3-e599-460d-9b99-3bce04489557
< 5.2.1
HIGH 8.8 The RD Station plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.0.… wordfence
da9b1132-fb02-443d-8d56-9e89658aad89
< 1.20
HIGH 8.8 The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction … wordfence
da24aad2-ae6b-411e-a229-0df585215731
< 2.9
HIGH 8.8 Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit F… wordfence
da025593-ad11-4a48-97e1-d31c6f0e62ea
< 1.2.7.31
HIGH 8.8 The Breezing Forms plugin for WordPress is vulnerable to generic SQL Injection via the ‘page’ parameter in versions … wordfence
d9fbd7ee-cfd0-4621-9eb9-df0202657ce9
< 1.3.5
HIGH 8.8 The crelly-slider plugin before 1.3.5 for WordPress has arbitrary file upload via a PHP file inside a ZIP archive to wp_… wordfence
d97b6f64-a596-4c83-8ab5-98b4b246897f
< 2.0
HIGH 8.8 The Formidable Form Builder plugin for WordPress is vulnerable to blind SQL Injection via the ‘orderby’ parameter in… wordfence
d96c9b04-6850-40ab-8006-81cca8a9dffe
< 1.7.8
HIGH 8.8 The CM Ad Changer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Banner Title field in versio… wordfence
d9606d92-8061-4dfc-a6e2-509b54613277
< 3.7.10
HIGH 8.8 The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrust… wordfence
d93de33b-1715-4e86-9df0-c20625d455d1 HIGH 8.8 The IF AS Shortcode plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.… wordfence
d922fdf8-8bbb-4722-ad16-a013264085f2
< 2.0.3
HIGH 8.8 The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to Privilege Escalati… wordfence
d91ea0c9-ee41-4c8f-a16b-8b36c7f0a72e
< 3.6.1
HIGH 8.8 wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which … wordfence
d9108d5f-7b8b-478d-ba9d-f895bdb7dbf2
< 2.7.31.2
HIGH 8.8 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode … wordfence
d8ba4a74-6649-4566-b9d5-19662539158b
< 5.0.1.6
HIGH 8.8 The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action befo… wordfence
d8b544ba-8530-4c00-a8a8-b24d8b68a33a
< 2.1.0
HIGH 8.8 The Double Opt-In for Download Plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in… wordfence
d872ec33-6284-495c-b894-41fe7b40b63c HIGH 8.8 The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing f… wordfence
d85b98c3-c912-4467-962c-eb64465266b2 HIGH 8.8 The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a S… wordfence
d847e26b-8c11-4612-84d7-ff319ca374dc
< 1.8.0
HIGH 8.8 The Elementor Website Builder plugin for WordPress is vulnerable to missing authorization in versions up to, and includi… wordfence
d83d1fd0-6e21-406e-a7c0-89d26eabbb32 HIGH 8.8 The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2… wordfence
d831fa81-4714-4757-b75d-0a8f5edda910
< 1.6.9
HIGH 8.8 The Web Directory Free for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, a… wordfence
d82efaa3-ea61-476c-ad1a-60585450c63a
< 2.0
HIGH 8.8 The Contact Form 7 Email Add on plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in… wordfence
d81ed8d9-4a7a-4b75-aab4-8e4dbd554f32 HIGH 8.8 The Mediamatic – Media Library Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
d80d583f-42c8-48fb-b757-88346c740b0e HIGH 8.8 The eExamhall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0. Th… wordfence
d8029737-f3ad-4025-948a-ba0298c0869d
< 1.26.2
HIGH 8.8 The WP Job Manager plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and mi… wordfence
← Prev 123 124 125 126 127 128 129 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top