ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 127 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d7f4e710-99a2-49df-a513-725e1daaa18a
< 1.2.1
HIGH 8.8 The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… wordfence
d7f0f654-e455-4284-ba44-35f1fbcbb3ba HIGH 8.8 The Sale! Immigration law, Visa services support, Migration Agent Consulting theme for WordPress is vulnerable to Privil… wordfence
d7e7247f-869a-4cf0-ae03-0b36ecbc1b7e
< 3.1.3.1
HIGH 8.8 The Crocoblock JetEngine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… wordfence
d7c98191-bf17-4e94-88cc-ad385b1fe97d HIGH 8.8 The Auto Thumbnailer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
d7b7b31a-2bc4-42b7-ba60-0f29fe65bbe7 HIGH 8.8 Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit éŸ³ä¹æ’­æ”¾å™¨ plugi… wordfence
d79dc179-8f0e-47e3-9697-82d9c9d44be2 HIGH 8.8 The WP Masquerade plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.0… wordfence
d764b1be-b4ae-4845-b506-846f782cf21e HIGH 8.8 The Private Files WordPress plugin through 0.40 is missing CSRF check when disabling the protection, which could allow a… wordfence
d74efb03-4a1c-4163-bd79-ef17975a609e
< 1.9.0
HIGH 8.8 The Export Import Menus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
d7220537-aad0-48e0-81f1-7104ec15ffbe
< 1.3.1
HIGH 8.8 The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are … wordfence
d6fbf684-8651-484d-9459-ed11d6d9008f
< 1.1
HIGH 8.8 The SB Random Posts Widget plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, … wordfence
d6fb275b-dbba-46df-b170-977ef4a84c4c
< 4.1.17
HIGH 8.8 The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload … wordfence
d6dfed14-bb6f-4418-bdd8-9c548e63dac0
< 4.6
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.… wordfence
d6d394af-67b0-4754-bdec-6ee89b7e8bbd
< 2.7.7
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in admin/setting.php in the Xhanch - My Twitter plugin before 2.7.7 for … wordfence
d676700b-8c53-4e09-a654-767810b5a775 HIGH 8.8 The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2.… wordfence
d6572568-5586-4ed9-b0e2-32509b42ed31
< 2.8.4
HIGH 8.8 The Welcart e-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
d6489214-2155-47f4-83ef-0119b3c26e43
< 1.8.3
HIGH 8.8 The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution W… wordfence
d6206d7e-90b9-43fd-a6cd-90e98162cd09
< 1.2
HIGH 8.8 The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface. wordfence
d60fb13c-cba8-466a-8881-1ed835881b79 HIGH 8.8 The Flash News / Post (Responsive) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
d60e1a2c-a3f1-4c39-a22f-9c09d0fed2c5
< 1.1.1
HIGH 8.8 The stats plugin for WordPress is vulnerable to SQL Injection via the $post_ids parameter in versions up to, and includi… wordfence
d60b5741-5496-4e87-bcb0-adaa0db07d90
< 1.21.12
HIGH 8.8 The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vu… wordfence
d5b110a5-4027-4c98-a348-325c8b9c8405
< 14.1.00
HIGH 8.8 The WooCommerce Amazon Affiliates - Wordpress Plugin plugin for WordPress is vulnerable to privilege escalation in all v… wordfence
d5a0c514-5200-47f4-9d2e-684d68946b9a
< 1.4.6.1
HIGH 8.8 The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.… wordfence
d560f28f-899c-44cf-8640-55647c1de7dc HIGH 8.8 The ScrollTo Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in version… wordfence
d557db81-9689-4fc1-b749-3595859048de
< 1.3.2
HIGH 8.8 The Testimonial Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
d539dc3f-ebb9-40d6-9016-7d52935e2575
< 7.3.8
HIGH 8.8 The GamiPress plugin for WordPress is vulnerable to Local File Inclusion via the gamipress_logs_shortcode() function in … wordfence
← Prev 124 125 126 127 128 129 130 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top