🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 128 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d52e644b-a58f-4e09-9e53-e9cbef75e34f
< 1.2.0
HIGH 8.8 The Email Notifications for Updates plugin for WordPress is vulnerable to unauthorized modification of data that can lea… wordfence
d51db160-c701-426d-890f-73cc4785cad8
< 2.0
HIGH 8.8 The Restaurant Reservations plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ… wordfence
d4c5a982-74ba-4a54-8c95-515a628f9c39 HIGH 8.8 The FLV Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. … wordfence
d4a905c0-f958-4c9b-9e96-dd8653b50497
< 2.2.29
HIGH 8.8 The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is… wordfence
d43234d0-5f44-4484-a8d6-16d43d1db51e
< 4.0.8
HIGH 8.8 The WP Dark Mode plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.7 via … wordfence
d42b8856-e5d0-4122-98a4-8c959832b271
< 10.2.0
HIGH 8.8 The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0… wordfence
d420ee49-e7b3-43d8-a263-8a93abd1133c
< 11.15.3
HIGH 8.8 The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida… wordfence
d4185a0e-d944-408f-8a43-8f9c6bc3964d
< 7.5.47.7212
HIGH 8.8 The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ para… wordfence
d3d26aa4-8bea-48e8-ad14-513690a31831
< 1.1.28
HIGH 8.8 The Button plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.27 via d… wordfence
d3b80f57-881f-4b97-8c5f-78317ea0b86b HIGH 8.8 The Pop-Up Chop Chop plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.7.… wordfence
d3b62eb2-6c03-4e24-a454-5de54a4521b2
< 7.11.2
HIGH 8.8 The Avada theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation when extractin… wordfence
d3adabcc-3259-4d4d-8359-71af16823d18 HIGH 8.8 The Login Block IPs plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
d39a73dd-5d62-43cc-af36-6bdf85dec3f1
< 1.4
HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the Newsletter Manager plugin before 1.4 for WordPress all… wordfence
d37b10f7-ea20-47cb-913a-4286c2ee2771
< 2.3
HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the IndiaNIC Testimonial plugin 2.2 for WordPress allow re… wordfence
d379bc09-7788-4a29-b23f-7f42afe04fd4
< 5.10.3.1
HIGH 8.8 The TheGem theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the thegem… wordfence
d35e2d84-12c7-4c01-bde9-2fb05583a212
< 2.10.15
HIGH 8.8 The PowerPack Pro for Elementor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and in… wordfence
d35266cd-41e6-4358-afaa-bc008962f2e1
< 1.4.0
HIGH 8.8 The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Inj… wordfence
d3326e9d-504f-444f-baf7-03989594f483
< 250419
HIGH 8.8 The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214… wordfence
d30cb60e-19a1-4720-abb0-c04a66894b6a HIGH 8.8 The Saksh Escrow System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4 due to… wordfence
d2e762b6-b3f2-4610-b7db-98c62e014d40
< 6.0.6
HIGH 8.8 The Widget Logic plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.0.5… wordfence
d2cc4dcc-f3d1-4425-aeb8-9ef51e79287d HIGH 8.8 The Pricing table addon for elementor plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and … wordfence
d2b66eca-67cf-404e-9c4b-6add0ee79141
< 1.0.16
HIGH 8.8 The Optinly plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.15. T… wordfence
d276af21-fa9d-46bd-94e3-03776d4f2238
< 1.5.3
HIGH 8.8 A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves a… wordfence
d25ed357-2895-47c7-9418-628068c6d18e
< 3.7.10
HIGH 8.8 The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrust… wordfence
d2550461-2546-4dc4-85ff-decf2fca3f10 HIGH 8.8 The Events Made Easy plugin for WordPress is vulnerable to a time-based SQL Injection via the 'search_name' parameter of… wordfence
← Prev 125 126 127 128 129 130 131 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top