πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1384 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d5c88ec9-f059-4f7e-975f-bc6e8f045191 MEDIUM 4.3 The Mergado Pack plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.… wordfence
d5c704f9-4fcb-455e-a1c7-f48d47b12dec
< 6.4.5
MEDIUM 4.3 The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
d5b573e2-373f-41bc-8d9a-ea42e908ac4e MEDIUM 4.3 The WCP OpenWeather plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
d5a4e980-afb7-416d-baa6-b8a25c5502b1
< 4.3.3
MEDIUM 4.3 The Edwiser Bridge plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
d5a49269-63de-413a-a16e-8bd1916c0151
< 2.0.3
MEDIUM 4.3 The UPC/EAN/GTIN Code Generator plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
d5a0483c-e7f9-4304-8997-e590023780e8 MEDIUM 4.3 The NanoSupport β€” Support Ticketing & Knowledgebase for WordPress plugin for WordPress is vulnerable to unauthorized a… wordfence
d5971b4c-50c7-43e7-b562-5c18ffebaddc
< 2.0.1
MEDIUM 4.3 The Block User Account plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 2.0.0… wordfence
d58fd503-84d0-4d62-9290-870b1dd32be7
< 1.8.2
MEDIUM 4.3 The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This… wordfence
d58e4317-8ad5-40d5-98b8-f8f07ab37e1f
< 3.9.3
MEDIUM 4.3 The Stream plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the lo… wordfence
d58ca75a-f425-477d-8e48-a5d600543578
< 2.3.2
MEDIUM 4.3 The FooGallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.44… wordfence
d57fa9f3-b1c0-4601-96d9-178d0dba1332 MEDIUM 4.3 The LazyLoad Background Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … wordfence
d56aaa20-f40c-4f99-bc38-0b14fa39a175 MEDIUM 4.3 The Kebo Twitter Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
d5522065-bc52-445a-a242-31a05dd95124 MEDIUM 4.3 The WP-DownloadCounter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
d54b4dc9-8590-433c-873a-efb49e2e79cd
< 3.6.4
MEDIUM 4.3 The Hueman theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.3. This… wordfence
d535eb0e-28df-46f3-8958-22701f9f15e7
< 2.3
MEDIUM 4.3 The Our Team Members – Team Members WordPress Plugin plugin for WordPress is vulnerable to unauthorized access of data… wordfence
d52a1c67-e20d-4390-9d07-94337a31d193
< 3.1
MEDIUM 4.3 The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… wordfence
d5217ca4-8155-4e38-9411-6e16afabfba5
< 1.4.4
MEDIUM 4.3 The Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to Se… wordfence
d51f0230-b85c-4c2d-9fa0-e68b52e51c76
< 2.1.0.14
MEDIUM 4.3 The WP Inventory Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
d50865b5-3910-4b26-8a4f-08922a2af230 MEDIUM 4.3 The Navegg Analytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
d504c2bd-d6a8-4a66-a650-4a18cb32c54a
< 3.16.6
MEDIUM 4.3 The 12 Step Meeting List plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability che… wordfence
d4dc4c7f-b5cd-4090-a303-4386af935712 MEDIUM 4.3 The Verdure - Organic Tea Shop WordPress Theme theme for WordPress is vulnerable to Insecure Direct Object Reference in … wordfence
d4dacd15-85cc-41f5-830c-b02c85c798f9
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
d4d7a36f-0210-43e8-b95c-f8666bf70aac
< 4.2.0
MEDIUM 4.3 The Order Delivery Date for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
d4ce9465-8158-4046-8195-5a82e6beb8d9 MEDIUM 4.3 The WP Supersized plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
d4c79242-5c89-40c0-abcc-c112f7a64a74
< 1.2.0
MEDIUM 4.3 The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of… wordfence
← Prev 1381 1382 1383 1384 1385 1386 1387 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top