πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1383 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d6d3396d-708d-45de-b32a-66e17624dc62
< 6.5
MEDIUM 4.3 The wp-Monalisa plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4. … wordfence
d6cef95b-3826-497c-8908-b5f24701d7e7 MEDIUM 4.3 The Watcher for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
d6bb08e8-9ef5-41db-a111-c377a5dfae77
< 2.4.0
MEDIUM 4.3 The Duplicate Post Page Menu & Custom Post Type plugin for WordPress is vulnerable to unauthorized page and post duplica… wordfence
d6b8ba69-aa8b-436f-990c-39e283f5d2f2
< 1.4.12
MEDIUM 4.3 The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1… wordfence
d69915e9-af9b-4c07-ac43-21c6e350c3c4
< 6.1.6
MEDIUM 4.3 The Awesome Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6… wordfence
d68e250e-d850-4100-81db-3e3c48a3a4a1
< 1.0.28
MEDIUM 4.3 The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable… wordfence
d6888b76-2419-4adc-b641-58602303ab30 MEDIUM 4.3 The Bulk Fields Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
d6879547-4a5f-48af-a3af-7e13c941b4bf
< 2.7.0
MEDIUM 4.3 The Tracking Code Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
d6878dcf-a878-444e-a647-463c3bafb234
< 3.4.5.1
MEDIUM 4.3 The Watu Quiz plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
d67b1a6c-001d-452e-861c-0e5c7ab465dd
< 2.0.1
MEDIUM 4.3 The Generate Child Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
d66d6f36-ad16-40ba-b32f-f4aff6f8b494
< 1.2.5
MEDIUM 4.3 The Upcoming for Calendly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
d6628232-0bd1-4194-8322-36084b1eb0f7
< 1.9.3
MEDIUM 4.3 The Hot Random Image plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.9.2 vi… wordfence
d6516fc0-4ef8-423b-9cdb-a275996fd98b
< 5.3.0
MEDIUM 4.3 The WP Basic Elements plugin for WordPress is vulnerable to modification of data due to a missing capability check on th… wordfence
d6421c33-152d-4e50-a96c-f97e2981b72f
< 1.0.6
MEDIUM 4.3 The RD Order Modifier for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
d63a8ec5-043d-4263-a7f3-8c117d1fb0b7
< 3.37.3
MEDIUM 4.3 The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to Sensitive In… wordfence
d63a1a9e-bdba-4987-b3e9-48ef1cf9be5b
< 1.6.2
MEDIUM 4.3 The Contact Form By Mega Forms – Drag and Drop Form Builder plugin for WordPress is vulnerable to unauthorized access … wordfence
d638120b-5396-408b-8273-d003ff9dd01d
< 2.3.2
MEDIUM 4.3 The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied… wordfence
d6331b42-f15b-46c6-b8bd-7f65c28c4a12
< 2.7.3
MEDIUM 4.3 The Slider by Soliloquy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch… wordfence
d6302ecb-07a1-4b80-a5f5-be6b623c7c9f MEDIUM 4.3 The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0… wordfence
d624f234-c57a-4a66-900d-362194a79d34
< 2.4.1
MEDIUM 4.3 The WooCommerce Dynamic Pricing and Discount Rules plugin for WordPress is vulnerable to Cross-Site Request Forgery in v… wordfence
d6198e3e-a8e8-4d67-a0d6-b62f187d4903
< 2.15
MEDIUM 4.3 The BestWebSoft's Twitter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
d6006ffe-e2db-477f-8a9f-c0cf0434086b MEDIUM 4.3 The xShare plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1.… wordfence
d5f4c4ec-bdb5-4f27-8ee3-060de9b62502
< 1.6.3
MEDIUM 4.3 The Medical Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions u… wordfence
d5f1ceb3-34b6-4d97-9787-d52a92f84662
< 3.5.2
MEDIUM 4.3 WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive inf… wordfence
d5c9f08b-c02c-44e1-a8ae-3a2b1e06508a
< 4.3.5
MEDIUM 4.3 The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to unauthorized … wordfence
← Prev 1380 1381 1382 1383 1384 1385 1386 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top