🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1381 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d8ce9ab4-d6d6-4e06-a042-145db02cf7ba
< 1.9.0
MEDIUM 4.3 The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Cross-Site Request Fo… wordfence
d8afc698-b9dd-4da8-a3fe-1813a14f6acc
< 5.1.1
MEDIUM 4.3 The افزونه پرداخت امن زرین‌پال برای ووکامرس (ZarinPal for WooCommerce) plugin for Wor… wordfence
d8a490c6-14c1-4c71-b44c-1e362cc892a8
< 2.1.18
MEDIUM 4.3 The WooCommerce Multi Currency plugin for WordPress is vulnerable to Missing Authorization in versions up to, and inclu… wordfence
d8a0f5a3-fed8-4dac-b07a-46139a940665
< 3.0.8
MEDIUM 4.3 The Paid Member Subscriptions plugin for WordPress is vulnerable to unauthorized access in versions up to, and including… wordfence
d897fdc8-bc72-426b-89f6-9416f9a7d25d
< 1.0.4
MEDIUM 4.3 The Togo – Travel & Tour Booking WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a mis… wordfence
d877ca14-7dba-4c31-afef-7072bd5bfa02
< 3.3.6
MEDIUM 4.3 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized access due to… wordfence
d875c7b8-a508-4764-aa94-51c799698791 MEDIUM 4.3 The Caldera SMTP Mailer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
d86c720b-ede6-4789-ba83-2d035e1641bf
< 4.4.1
MEDIUM 4.3 The Gift Vouchers plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4… wordfence
d86aa41c-24df-49ec-b273-7bb57addddde
< 3.5.2.9
MEDIUM 4.3 The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to unauthorized loss of data due to a missi… wordfence
d85e54c2-dff6-42e6-8123-767438f9c5f1 MEDIUM 4.3 The Zass - WooCommerce Theme for Handmade Artists and Artisans theme for WordPress is vulnerable to unauthorized access … wordfence
d8582985-ce9c-49f2-a7c6-180117e3da28
< 1.6.8
MEDIUM 4.3 The RTMKit plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, … wordfence
d834eb3a-e887-40df-b61d-56ba32048aa3 MEDIUM 4.3 The ListingPro Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
d82e856b-c8c9-4139-ad54-89368e3b7125
< 2.2.8
MEDIUM 4.3 The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on t… wordfence
d811782e-3b59-4a46-9a2e-f24ef3dfbd4a
< 4.7.3
MEDIUM 4.3 The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in v… wordfence
d8074af6-cb2c-44db-9110-517f33caa96e MEDIUM 4.3 The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
d8045e14-dfeb-4d1b-8e72-861bc7f8b8ab
< 3.3.5
MEDIUM 4.3 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure … wordfence
d80417bc-2bb2-4826-be03-796a7cd2825f
< 3.2.1
MEDIUM 4.3 The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet plugin for WordPress is vulnerabl… wordfence
d7f21dbe-f300-4336-9980-a69d40395f39
< 2.3.3
MEDIUM 4.3 The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to … wordfence
d7d3862f-7221-4a70-af72-f0b997ad8d43 MEDIUM 4.3 The Woocommerce Role Pricing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
d7d20733-d61b-4b2f-8597-528644f0bc26
< 5.0.5
MEDIUM 4.3 The WP Dark Mode – WordPress Dark Mode Plugin for Improved Accessibility, Dark Theme, Night Mode, and Social Sharing p… wordfence
d7d08b06-975d-41a7-a297-ebbf0cca13b6
< 5.1.0
MEDIUM 4.3 The Church Admin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
d7c05856-fbee-498d-9e9f-f0a232df6d24
< 1.2.105
MEDIUM 4.3 The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve… wordfence
d7c03f9e-fd4e-4787-ae7c-8aff8c854730 MEDIUM 4.3 The Vireo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in ve… wordfence
d7befdf6-07d7-42c9-876a-abb8f8f9c3df
< 3.6.26
MEDIUM 4.3 The Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on t… wordfence
d7b40225-d994-43d2-8e8f-2dae271be9be
< 3.0.15
MEDIUM 4.3 The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to unauth… wordfence
← Prev 1378 1379 1380 1381 1382 1383 1384 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top