πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1382 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d7aaf9a6-0439-4458-9194-0ee4730f3e4e MEDIUM 4.3 The Searcher for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
d7a05894-8f9d-442f-961c-2e80aa25c3db MEDIUM 4.3 The WP-Backgrounds Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
d7a02502-bc3c-4fd1-b6db-7b3c476c141f
< 3.2.0
MEDIUM 4.3 The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1… wordfence
d79b092c-9e2c-4752-bf95-d3a6ac145073
< 1.3.1
MEDIUM 4.3 The WP SendFox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the gb_sf4… wordfence
d77b127e-52ee-4256-9450-410413b273f6
< 1.5.4
MEDIUM 4.3 The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized mod… wordfence
d77a47e9-0d34-4a88-a913-74a8ef972f9b
< 4.8.7
MEDIUM 4.3 The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable t… wordfence
d777014a-5397-4062-af39-7ea86589a0d0
< 21.0.10
MEDIUM 4.3 The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure D… wordfence
d76911c6-e185-47b2-a25f-167c29ac86db MEDIUM 4.3 The Martins Free Monetized Ad Exchange Network – Get more website visitors plugin for WordPress is vulnerable to Cross… wordfence
d75f6c80-ffbf-47a5-9180-5153b705cb28 MEDIUM 4.3 The Dyslexiefont Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
d75f1475-fa81-4eed-87da-0a0fa48ac082
< 1.6
MEDIUM 4.3 The Current Menu Item for Custom Post Types plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… wordfence
d75d0f16-015b-49cd-a0d1-41e007fc7398
< 3.4.4
MEDIUM 4.3 The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX … wordfence
d74c27bd-fc3e-4dc8-ba85-7f2208840eeb
< 5.3
MEDIUM 4.3 The CopySafe Web Protection plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
d74553a4-0ef7-4908-a2e8-5e0216f7b256
< 2.4.3
MEDIUM 4.3 The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
d74040d0-1fee-4906-af6f-a5d842c42fd4 MEDIUM 4.3 The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data d… wordfence
d7362f3f-c5d9-4ba0-b9c3-282c58861e2f
< 5.2.0
MEDIUM 4.3 The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable … wordfence
d72c8140-90f1-49f5-bc42-925e29ecc0b1
< 6.2
MEDIUM 4.3 The Video Playlist For YouTube plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
d7274e11-dcd4-471b-bfaf-ae90d0e4d7e6
< 7.2.2
MEDIUM 4.3 The WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce plugin for WordPress is vulnerab… wordfence
d7184e6d-ae46-4725-b464-b9ccb5d518e1
< 1.7.9
MEDIUM 4.3 The FundEngine plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
d70e9d4e-2137-411b-bc01-28388a7b2519 MEDIUM 4.3 The SpamReferrerBlock plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
d707d766-a46d-49f5-b1be-a9b9e423e61e
< 1.5.8
MEDIUM 4.3 The VOD Infomaniak plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
d6ffc8de-e8e4-41b6-a4b9-79511fb950fc MEDIUM 4.3 The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to … wordfence
d6fb5839-c4c3-422d-8418-5f4dc36cdb39 MEDIUM 4.3 The Real Time Validation for Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… wordfence
d6eb878a-6f4b-4668-993d-d33a50abd618
< 1.4.8
MEDIUM 4.3 The Paytiko for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
d6de5295-cb13-4e53-bcb2-3fc6c95b849a MEDIUM 4.3 The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
d6dcbd8c-018e-4c1b-8827-792300b3a5b1
< 1.30.1
MEDIUM 4.3 The Name Directory plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
← Prev 1379 1380 1381 1382 1383 1384 1385 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top