πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1379 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
daac833f-b350-453a-b56a-fe3b1dd2ed3b
< 5.8.5
MEDIUM 4.3 The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for Wor… wordfence
daaa6507-cd8a-40c9-95af-34cc96551417
< 0.3
MEDIUM 4.3 The Tweet Wheel plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 0.2. This i… wordfence
daa8f941-6e87-4b94-8526-f73770fe6f82
< 3.0.68
MEDIUM 4.3 The Search, Filters & Merchandising for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of d… wordfence
daa30370-0d11-45b7-8ca3-b2a3b9046127
< 1.10.3
MEDIUM 4.3 The NitroPack plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.2.… wordfence
da8d1659-c532-4020-be16-527c1437952a
< 4.6
MEDIUM 4.3 The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data… wordfence
da78fd0a-f69f-4779-bcf1-df1dab80156c
< 5.0.9
MEDIUM 4.3 The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
da744a22-bfb2-4bbe-ab22-f18cec945a3a
< 3.6.16
MEDIUM 4.3 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthor… wordfence
da6bf1b8-4bac-4c3a-a32f-fd157e77fce0
< 3.2.1
MEDIUM 4.3 The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerabl… wordfence
da680b46-620c-4d35-a327-c7ebe08e49c4
< 2.2.0
MEDIUM 4.3 The Radius Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1… wordfence
da4592b6-5e84-4a89-9ade-6cc227740d32
< 2.5.6
MEDIUM 4.3 The Sell Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.5.… wordfence
da3c736d-7b10-4f7b-a034-83981fbe53ca MEDIUM 4.3 The Printeers Print & Ship plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
da2b7267-936b-4011-af42-210885d5dbb9 MEDIUM 4.3 The Posts reminder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
da1f68a5-8ca7-4744-9b73-09e767072885
< 2.0.9
MEDIUM 4.3 The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to … wordfence
da09b158-3626-455b-b3bc-b1109d0fab2e MEDIUM 4.3 The Advanced Category Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
da02bc67-466b-4e20-bbe0-728a4ee9f415
< 1.48.1
MEDIUM 4.3 The YITH WooCommerce Popup plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
d9ffc0af-9c3d-4f8e-ae0b-e51c0c67dfe1
< 3.3.0
MEDIUM 4.3 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object Ref… wordfence
d9fcb387-fee5-4ad3-b51f-ac506b48882c
< 4.1.2
MEDIUM 4.3 The Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant plugin for WordPress is vulnerable to Cross-S… wordfence
d9f7f66f-5d58-4a23-8444-805569ec8294
< 2.6.1
MEDIUM 4.3 The Church Content – Sermons, Events and More plugin for WordPress is vulnerable to Cross-Site Request Forgery in vers… wordfence
d9f7130d-883a-4db4-9edf-f5526724de11
< 3.0.3
MEDIUM 4.3 The MakeStories (for Google Web Stories) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
d9f6b600-a35a-49c2-8758-a7cc5c00e947
< 4.3.1
MEDIUM 4.3 The Customizr theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.0. T… wordfence
d9f3756a-8d03-471d-afb8-05d17ebbfcfc
< 2.4.6
MEDIUM 4.3 The Easy Booked – Appointment Booking and Scheduling Management System for WordPress plugin for WordPress is vulnerabl… wordfence
d9e5cbde-6bc6-49f2-91b4-86c1779de2dc
< 4.4.1
MEDIUM 4.3 The Groundhogg β€” CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to unauthorized access … wordfence
d9d46dbc-35ed-4520-a5d3-e2bd8d93c5a6 MEDIUM 4.3 The WP Admin Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
d9cf6dae-572f-4eaa-8e8a-bca9e74fe738
< 2.9.2
MEDIUM 4.3 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss o… wordfence
d9ce0bef-da72-441a-8de0-89c77115a38c
< 1.3.0
MEDIUM 4.3 The Appointment Booking Plugin for WooCommerce – WpBookingly | All-in-One Service Manager plugin for WordPress is vuln… wordfence
← Prev 1376 1377 1378 1379 1380 1381 1382 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top