πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1283 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d4c8333f-1570-4bf2-a7d0-cce705e88f27
< 4.0.9
MEDIUM 4.4 The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
d3f9e624-c176-403c-a3c5-7bd11027ebe5 MEDIUM 4.4 The LetterPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in versions up to,… wordfence
d3d795f5-c79a-4615-be1f-120a6ffd663d
< 3.6.26
MEDIUM 4.4 The Ninja Forms plugin for WordPress is vulnerable to Stored HTML Injection in versions up to, and including, 3.6.25 due… wordfence
d3bd7b0e-aae3-4ac9-b092-3101da441e1e MEDIUM 4.4 The Decon WP SMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions u… wordfence
d3ae776f-65d7-4bb5-9368-9cd22207ea98 MEDIUM 4.4 The Forty Four – 404 Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin … wordfence
d3abf6bd-bece-470e-93c7-ab9968171a3f
< 1.8.12
MEDIUM 4.4 The HD Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, … wordfence
d3945a60-6be2-4ce5-850e-a214523fb584
< 1.4.7
MEDIUM 4.4 The Crelly Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
d38762ea-fceb-4f98-a976-c1185f15ecf9 MEDIUM 4.4 The Pushe Web Push Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
d353d8b7-76a5-45ce-aa7c-d571dedcbfd4
< 3.8.3
MEDIUM 4.4 The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unspecified paramete… wordfence
d34936af-f3a4-414d-ad71-7ad3af6feed4 MEDIUM 4.4 The WP Emmet plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.3.4 d… wordfence
d3343d96-ca52-46a6-b464-cd2e5375d10f
< 3.1.0
MEDIUM 4.4 The Fathom Analytics for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
d2ea5e34-9303-43c8-8579-80ef02e1d9c4 MEDIUM 4.4 The Login Manager – Design Login Page, View Login Activity, Limit Login Attempts plugin for WordPress is vulnerable to… wordfence
d2ded652-1cca-400b-80ca-2aab1a1def8b MEDIUM 4.4 The Add & Replace Affiliate Links for Amazon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… wordfence
d2b66f27-e4d2-4f6e-be96-b7f967a30885
< 3.0.8
MEDIUM 4.4 The Klaviyo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and … wordfence
d2a3ad97-b4ea-4ad9-ac83-071e56cb8df7 MEDIUM 4.4 The Tiny Carousel Horizontal Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings… wordfence
d29c69bb-4feb-477e-b18f-934ece21aff6 MEDIUM 4.4 The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.… wordfence
d267a3d8-2fe3-48b2-95a1-49d3baa67694
< 2.9.5
MEDIUM 4.4 The Login/Signup Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
d21209a7-efed-4526-8dd6-199e0fdf8657
< 2.3.1
MEDIUM 4.4 The Ultimate Posts Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
d21187bc-5bd0-49b9-9ef2-6654263cd93c MEDIUM 4.4 The Just Highlight plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Highlight Color' setting i… wordfence
d1f957ce-7bb0-4701-8b2a-522211c408d8
< 1.5.1
MEDIUM 4.4 The iFolders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and… wordfence
d1f51f00-9991-49b3-950a-4a12667991e4
< 1.7.10
MEDIUM 4.4 The Morkva UA Shipping plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
d1dd82a7-c9eb-4bc6-a9ae-0085392c68c5
< 2.8.110
MEDIUM 4.4 The GeoDirectory plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8… wordfence
d19e6433-c248-44ff-97a9-0f351eb77763
< 3.1
MEDIUM 4.4 The Product Enquiry for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings… wordfence
d1813e3a-0c42-4ac6-a3ee-168912dfdc44
< 4.4.2
MEDIUM 4.4 The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se… wordfence
d17d9610-d0fd-419d-a7ea-e9c313f1c542
< 2.4.9
MEDIUM 4.4 The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a… wordfence
← Prev 1280 1281 1282 1283 1284 1285 1286 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top