πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1380 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d9cd3168-3261-4e36-8fbe-2058cd821937
< 1.2.7
MEDIUM 4.3 The Easy Twitter Feed – Twitter feeds plugin for WP plugin for WordPress is vulnerable to Information Exposure in all … wordfence
d9c9de2f-e46a-4f68-abf4-225e96dcf5e7 MEDIUM 4.3 The pCloud Backup plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
d9c479fc-2e98-4851-a36c-2fd219e750ed MEDIUM 4.3 The Constructor theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
d9b15c1f-dee4-4df4-9c8b-d238e67c46d5
< 4.0.12
MEDIUM 4.3 The Post Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0… wordfence
d9af12ac-68ef-4c65-aecb-82ce7b927340
< 4.0.6
MEDIUM 4.3 The Responsive Tabs plugin for WordPress is vulnerable to Arbitrary Content Injection in versions prior to 4.0.6. This v… wordfence
d9906b19-1ac7-4015-adb3-0674dde0331e
< 2.1.0
MEDIUM 4.3 Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to create… wordfence
d97c19d6-511f-459a-9880-cdc1fe137205
< 0.6.4
MEDIUM 4.3 The AntiSpam for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
d97af468-d345-4d19-a1b0-f42d890a34d8
< 2.1
MEDIUM 4.3 The WP Performance Score Booster WordPress plugin before 2.1 does not have CSRF check when saving its settings, which co… wordfence
d9731e3a-4972-4e1e-b6cd-4bc00a6e9552 MEDIUM 4.3 The AZIndex plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8.1… wordfence
d96a3d43-81dd-4c23-984b-a9ddf450164b
< 5.7.3
MEDIUM 4.3 The wp-media-folder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
d964e0ef-f14e-463b-bf4e-3f25788df03c
< 1.3.14
MEDIUM 4.3 The Yuki theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the… wordfence
d95b01c3-5db4-40ac-8787-0db58a9cc3a6
< 1.7.2
MEDIUM 4.3 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
d9580a28-3c75-4e26-a688-204859edf7cb MEDIUM 4.3 The WordPress Graphs & Charts – Easy Interactive HTML5 Charts Plugin plugin for WordPress is vulnerable to unauthorize… wordfence
d94661c1-2d70-4943-9452-b51a76116ebb
< 7.1.2
MEDIUM 4.3 The Booster for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabilit… wordfence
d93e0175-db55-42ab-8475-cd0f47e5dcbb MEDIUM 4.3 The Duplicate Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
d93caec2-c2e6-4848-9f6d-5fb19d90929c
< 6.2.2
MEDIUM 4.3 The ThumbPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
d937ce1f-3948-4366-b395-fa401236f7a1 MEDIUM 4.3 The Brikk - Directory & Listing WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missin… wordfence
d9318d57-499b-4804-8f83-1e4a68c5790f
< 3.6.0
MEDIUM 4.3 The Inline Related Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and… wordfence
d93006ac-037f-4291-b945-afa38358a037
< 2.9.4
MEDIUM 4.3 The Contextual Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
d92b9c21-067b-41c3-a385-a65faa8dd0ae
< 1.0.8
MEDIUM 4.3 The TPG Redirect plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.… wordfence
d9189eb3-be7f-42e1-92cc-b48af5615eb9
< 3.2.3
MEDIUM 4.3 The Inactive Logout plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the… wordfence
d9125873-aedd-4334-b8e0-74b67d301904
< 2.3.10
MEDIUM 4.3 The SecuPress Free β€” WordPress Security plugin for WordPress is vulnerable to unauthorized modification of data due to… wordfence
d9022afe-0c79-413b-ac0a-a1d32ec09619
< 3.4.7
MEDIUM 4.3 The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bump… wordfence
d8f7b930-dad7-49ce-8826-8c8ab7b390ef MEDIUM 4.3 The Travelpayouts plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
d8d52ced-807b-48c0-bb7a-e40d143ae5d3
< 2.0.13
MEDIUM 4.3 The PropertyHive plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on th… wordfence
← Prev 1377 1378 1379 1380 1381 1382 1383 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top