πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1375 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
dee18143-3b95-42fe-a69c-1862f3d30237
< 1.3.9
MEDIUM 4.3 The CM WordPress Search And Replace Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… wordfence
ded3a14d-f8ac-46f9-843b-591a6b558556
< 1.3.2
MEDIUM 4.3 The Nanosoft theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
decba9c0-36ee-4f97-9cc8-b56039233d10
< 8.0.2
MEDIUM 4.3 Lack of CSRF checks in the ActiveCampaign WordPress plugin, versions before 8.0.2, on its Settings form, which could all… wordfence
deb2544f-75ac-4d6c-bec7-9f35cfe0028d
< 1.2.2
MEDIUM 4.3 The HT Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. Th… wordfence
dea4a7f4-e075-45d9-bf71-f411f4ce30df
< 3.1.3
MEDIUM 4.3 The Prodigy Commerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
de7b68e2-9cae-4e6f-a625-d8346836da39 MEDIUM 4.3 The MF Gig Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
de69d597-b663-4c58-82e0-c90391fb8416
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability c… wordfence
de62020b-5803-4ea7-89a1-24e5a512f2f3
< 4.5.11
MEDIUM 4.3 The WPML plugin for WordPress is vulnerable to missing authorization checks in versions up to, and including, 4.5.10. Th… wordfence
de6048e7-75c6-44b1-bc68-e36dce936c78 MEDIUM 4.3 The Category SEO Meta Tags plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
de53b1d8-e38f-42c5-adfc-2b0ce8d6945b MEDIUM 4.3 The Typer Core plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.6 vi… wordfence
de495201-669c-4483-b30d-bb2abf6fe6c6
< 5.7.7
MEDIUM 4.3 The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to Insecure Di… wordfence
de46743b-2cc6-4a29-bbc4-bc6cfb540e26
< 4.1.6
MEDIUM 4.3 The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due… wordfence
de249879-00b8-49b3-8964-f7ab69ab292f
< 5.1.0
MEDIUM 4.3 The GDPR Cookie Compliance plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
de112e5a-4b92-4389-8c6e-b2bfeb6f6cd4 MEDIUM 4.3 The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to Cross-Si… wordfence
de00d13b-fab9-4284-9594-abd000fbb7ef
< 1.12.0
MEDIUM 4.3 The WP Mail Logging plugin for WordPress is vulnerable to unauthorized notice dismissal due to a missing capability chec… wordfence
ddfc0150-d05c-4027-80d2-64c565fdd56d
< 4.1.1
MEDIUM 4.3 The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
ddfba11c-eaa6-4c9e-9422-9390d433f24f
< 6.50.05
MEDIUM 4.3 The WP Compress for MainWP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
ddee10e0-093c-47a3-8aa9-946d6d21e1b2
< 4.3.7
MEDIUM 4.3 The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… wordfence
dde63254-058d-4151-b79e-33029c03decf MEDIUM 4.3 The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
dddecb2e-9ad6-4e44-afce-5eba7da6322d
< 7.7.12
MEDIUM 4.3 The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable t… wordfence
ddd85ff2-6607-4ac8-b91c-88f6f2fa6c56
< 3.3.2
MEDIUM 4.3 The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_payment_sta… wordfence
ddc29341-a23e-4694-b852-90794c01473a
< 2.2.5
MEDIUM 4.3 The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to … wordfence
ddacd612-0cd5-4b07-9184-bec6f1adbb4c
< 2.0.8
MEDIUM 4.3 The Simple 301 Redirects by BetterLinks plugin for WordPress is vulnerable to unauthorized enabling of plugin usage trac… wordfence
dda9aa4a-bac7-4aa1-b0c3-c8e37b1fbe70
< 3.4.1
MEDIUM 4.3 The WP HTML Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.… wordfence
dda43cdd-f0bb-4448-a067-1c9fb07b88ea MEDIUM 4.3 The Event Rocket plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
← Prev 1372 1373 1374 1375 1376 1377 1378 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top