πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1387 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d2e3ac14-1421-49f0-9c60-7f7d5c9d7654
< 4.6.20
MEDIUM 4.3 The B2BKing plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '… wordfence
d2e10791-7158-47ae-85c9-4a5a53b25d68
< 4.4.9
MEDIUM 4.3 The WordPress Books Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
d2d4c7ff-ecd3-4cfb-9466-08f3e6c4bd48
< 3.1.4
MEDIUM 4.3 The Intuitive Custom Post Order plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
d2d4508d-91ae-47a0-b11f-fec469686dc7
< 1.2.3
MEDIUM 4.3 The CM Table Of Contents – WordPress TOC Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… wordfence
d2d23e6f-d48f-4734-95f8-12bd58eb1c2f
< 5.10.13
MEDIUM 4.3 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for… wordfence
d2cf310d-b8ea-4960-8288-b31633e6b6ef
< 1.29
MEDIUM 4.3 The WP Attractive Donations System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
d2cee46a-03d5-4a31-ba15-28be97794199
< 1.5.1
MEDIUM 4.3 The USS Upyun plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5… wordfence
d2c2a02a-6282-4109-a503-bbe78b3627be MEDIUM 4.3 The TOCHAT.BE plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.4. … wordfence
d2c0be66-b2e9-4afd-a804-cc432b3fc694
< 4.5.4
MEDIUM 4.3 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to unauthorized access in a… wordfence
d2b3612e-3c91-469b-98ef-fdb03b0ee9d9
< 3.9.7
MEDIUM 4.3 The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the m… wordfence
d2b32fdc-b73f-48e5-88bf-e836ec2f791f
< 2.20.32
MEDIUM 4.3 The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
d2b16d43-6bd3-4ed2-9824-40a9458433bd
< 1.2.4
MEDIUM 4.3 The Theme Builder For Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
d2a60cb2-fe7d-4c51-9995-5cb4682d9d26
< 17.0.27
MEDIUM 4.3 The Multi-column Tag Map plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check o… wordfence
d295f424-8e18-4a32-8d96-94ce931d125b
< 3.20.4
MEDIUM 4.3 The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
d283527a-a955-4f82-9827-81a71158d8e2
< 1.58
MEDIUM 4.3 The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
d274f8b1-0f7c-44cc-8063-3d04a33a9404
< 1.4.0
MEDIUM 4.3 The TeraWallet plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.24… wordfence
d266b6ee-24ec-4363-a986-5ccd4db5ae3c
< 3.4.3
MEDIUM 4.3 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of da… wordfence
d257c128-dcab-49c6-9664-0cc393dcc4d9
< 1.23
MEDIUM 4.3 The Additional Order Filters for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
d230a727-0838-4b64-99f6-c91a362aacf7
< 1.3.0
MEDIUM 4.3 The Appointment Booking Plugin for WooCommerce – WpBookingly | All-in-One Service Manager plugin for WordPress is vuln… wordfence
d22e1b63-6ec9-4c06-9616-d976a8a83769
< 2.0.9
MEDIUM 4.3 The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vul… wordfence
d2230151-fde2-43d6-8bff-0d2ffd559ab3
< 3.0.5
MEDIUM 4.3 The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
d21dc02f-789c-497e-9d01-02fa49bf9e30 MEDIUM 4.3 The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
d2183a22-fba5-48d2-a68a-6914f04fb902
< 2.2.5
MEDIUM 4.3 The WooCommerce UPS Shipping – Live Rates and Access Points plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
d2053171-a213-43bf-bd15-2f42a178c3a8
< 5.0.0
MEDIUM 4.3 The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a miss… wordfence
d1f9a46c-5702-448a-b97b-3e2ba107737a
< 1.3.34
MEDIUM 4.3 The HTML Forms – Simple WordPress Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… wordfence
← Prev 1384 1385 1386 1387 1388 1389 1390 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top