πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1385 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d4b6d2c6-d157-4c4c-b6e1-557b8353c742
< 1.0.3
MEDIUM 4.3 The Auto Tag Creator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
d4a15720-2535-4258-8d58-20818cdbd413 MEDIUM 4.3 The Title Experiments Free plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
d49cdae7-4a95-494d-81da-a93e3c764ee7 MEDIUM 4.3 The Lazy content Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
d49b8c44-4dad-4990-a8a8-116b424a7dfa
< 1.2.2
MEDIUM 4.3 The Post Meta Data Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
d49b404f-4683-410b-884e-2c11218a3204
< 2.5.0
MEDIUM 4.3 The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnera… wordfence
d49a85d9-dea4-4632-adf7-c29b71b12c50 MEDIUM 4.3 The Build App Online plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
d48f98cb-18d5-4b15-96cb-94a4c86148e4
< 1.1.1
MEDIUM 4.3 The RealPress – Real Estate Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
d484500f-c8c1-4278-8a38-82a7fd5674f9
< 1.0.35
MEDIUM 4.3 The ProjectHuddle Client Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… wordfence
d4828a91-fd56-4c38-8666-d296721120e9 MEDIUM 4.3 The Smart WeTransfer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
d47f7d6f-7535-4117-b0da-b27811f733e6 MEDIUM 4.3 The sevenstars theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4… wordfence
d472011d-1623-4791-9d56-715d90fe0469
< 3.0.3
MEDIUM 4.3 The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability c… wordfence
d46f7a3e-b444-42ce-bf5d-e93a83167181 MEDIUM 4.3 The Fiorello theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including,… wordfence
d4655236-7dfe-40ae-9d0c-6eacc59af13d
< 1.3.1
MEDIUM 4.3 The Hide Dashboard Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… wordfence
d44a45fb-3bff-4a1f-8319-a58a47a9d76b
< 2.8.6
MEDIUM 4.3 The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
d440b7fc-e094-49b7-91d0-8f0d54e6ce83 MEDIUM 4.3 The Grand Blog theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1. Th… wordfence
d433a5b3-4661-4246-ae60-8a99633372ad
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
d4271fde-ce9e-416e-8f7d-661a3e777a5d MEDIUM 4.3 The Meks Quick Plugin Disabler plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
d411982d-4ed3-4dd5-9a18-111c15aa641b MEDIUM 4.3 The Multilanguage by BestWebSoft plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
d40e9d1c-8693-467f-a0e3-1000c6635a25
< 1.3.10
MEDIUM 4.3 The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
d3efaa0d-8af6-4cdf-9225-8bbcfdbb73d3
< 3.3.50
MEDIUM 4.3 The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… wordfence
d3ee118c-b8cd-4bac-97bd-508efdfa1a1e
< 1.0.3
MEDIUM 4.3 The Disable Elementor Editor Translation plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
d3e6185e-b07c-4ce3-a2b4-971c88e10bc0 MEDIUM 4.3 The Stratus theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
d3cd468e-424c-48bb-bc1f-cb8f8c3ccb20
< 5.8.5
MEDIUM 4.3 The wp-google-map-gold plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
d3ca4c3c-2b20-42d4-8dcf-77f4d52c25a3
< 2.0.1
MEDIUM 4.3 The Square theme for WordPress is vulnerable to unauthorized plugin activation due to a missing capability check on the … wordfence
d3c6fb8b-9df8-4cf5-b9e6-702852bb1977
< 0.7.1
MEDIUM 4.3 The PixFields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.7.0. … wordfence
← Prev 1382 1383 1384 1385 1386 1387 1388 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top