🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1376 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
dd9826d7-f8f5-4d3d-8145-3d4e6a63d784
< 1.10.2
MEDIUM 4.3 The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
dd8c45c7-dbb2-46ab-8e50-e02062587b00 MEDIUM 4.3 The Stopwords for comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
dd80abd9-3f41-414a-a781-9bff7d85ec4b
< 8.0.10
MEDIUM 4.3 The Tripetto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0.… wordfence
dd784fce-67a1-4740-9b0e-dcf54342f018
< 2.0.8
MEDIUM 4.3 The Zoho Campaigns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
dd6b5d6d-5f5b-4b38-a25a-02cc1c041d37
< 1.2.0
MEDIUM 4.3 The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of… wordfence
dd52a6b2-8241-444c-9db7-c5a57576de5e MEDIUM 4.3 The Printeers Print & Ship plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
dd4719c5-c9ad-42b2-adb8-9dc4d79406ab
< 3.2.26
MEDIUM 4.3 The Pixfort Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
dd40d6dd-37e8-4f42-9feb-b62830a0c37d
< 1.4.2
MEDIUM 4.3 The AIcomments – комментарии и отзывы ChatGPT plugin for WordPress is vulnerable to Cross-Site Reque… wordfence
dd248b4b-e7a6-4997-81d8-1d163cd85a9b
< 1.2.5
MEDIUM 4.3 The PopularFX theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4. T… wordfence
dd0eb569-b526-48bd-8198-ff883860e040
< 1.5.6
MEDIUM 4.3 The Child Theme Creator by Orbisius plugin for WordPress is vulnerable to unauthorized modification of data due to a mis… wordfence
dd0a7489-8e67-4bea-8071-c7f6ffa1b7ed
< 1.0.12
MEDIUM 4.3 The Year Make Model Search for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
dd0a4212-fe04-4c3b-9d78-b1a0bf97e274
< 7.1.3
MEDIUM 4.3 The Booster Plus for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa… wordfence
dcfcb5e8-99e1-4dde-b62e-9f2bfc7db6ef
< 5.9.3.1
MEDIUM 4.3 The ProfileGrid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.9.… wordfence
dceca4ee-6587-4eaa-974e-a21e7a10b6e8
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability c… wordfence
dcd7204f-d950-4fb8-beb2-d9f619824fa1
< 2.2.5
MEDIUM 4.3 The All in One SEO plugin for WordPress is vulnerable to Authenticated Privilege Escalation leading to Post Changes in v… wordfence
dcb0334c-d5eb-40b9-be7c-42857dedc96d
< 1.0.7
MEDIUM 4.3 Several Extend Themes themes for WordPress are vulnerable to Cross-Site Request Forgery in multiple versions. This is du… wordfence
dc9e818d-811e-4732-9c74-8eb6753a1706
< 1.1.9
MEDIUM 4.3 The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to C… wordfence
dc988ec1-d4d9-4805-bffc-85649df3c2cb
< 6.10
MEDIUM 4.3 The onOffice for WP-Websites plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
dc931943-13f3-4ab1-b70f-c234253ca269
< 2.7.5
MEDIUM 4.3 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions … wordfence
dc912011-64f1-4714-874f-3326e8981cd6 MEDIUM 4.3 The ZipList Recipe Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
dc8eea10-3c51-4147-a7f6-d73553158f84
< 2.5.8
MEDIUM 4.3 The Simple Custom Post Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… wordfence
dc8bef03-51e0-4448-bddd-85300104e875
< 1.3.88
MEDIUM 4.3 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
dc8704f2-01ee-4193-ae8d-96a7f5383d21
< 16.26.7
MEDIUM 4.3 The WP-Recall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 16.26.6… wordfence
dc821f8e-a10e-4c24-9702-4207789e34d6 MEDIUM 4.3 The Useinfluence plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
dc7b51e5-6eb7-41ba-add3-f083fb34c5e1
< 1.1.2
MEDIUM 4.3 The Advanced Popups plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
← Prev 1373 1374 1375 1376 1377 1378 1379 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top