πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1388 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d1f48424-6d1b-4fc3-a20b-f6f1e066da86
< 1.6.1
MEDIUM 4.3 The Solace Extra plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
d1e65ea8-b4d2-4912-a71a-7b7142311075 MEDIUM 4.3 The Gmail SMTP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.7.… wordfence
d1e3a7d8-d303-4638-8dc9-c62302cfa5fb MEDIUM 4.3 The FastPicker, an order picker and order management system (oms) for WooCommerce on steroids plugin for WordPress is vu… wordfence
d1e041f0-3019-4d1f-b1a3-b40275c0966a
< 1.9.16
MEDIUM 4.3 The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized acc… wordfence
d1de5088-c307-4e61-91cf-082c00f93c5b
< 2.2.2
MEDIUM 4.3 The Import into Easy Property Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
d1cf560e-8d55-4ccd-b939-4186cee0c0a9
< 2.0.20.2
MEDIUM 4.3 The JetPopup plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including… wordfence
d1c9da9c-8a92-44fd-a35a-4c6d3777901f
< 6.6.2
MEDIUM 4.3 The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadat… wordfence
d1c597ac-9ac9-4eef-be83-16dc36c32463
< 3.1.0
MEDIUM 4.3 The Deliver via Shipos for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
d1ba4b18-ff46-45ef-b7d4-0a314cf2d74c
< 1.4.2
MEDIUM 4.3 The Laposta Signup Basic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
d1b92249-bc18-4939-aefa-286667f6c003
< 1.0.0
MEDIUM 4.3 The ActivityPub plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including,… wordfence
d1a6bdc8-ae74-4d0b-9c47-f4bf69158a44
< 2.9.21
MEDIUM 4.3 The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
d19df1f1-df64-4b4a-8dcb-8c76566fc2ec
< 1.4.2
MEDIUM 4.3 The Organization chart plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on t… wordfence
d19b433f-2245-4ba3-8f46-36a184c2454d
< 2.77.0
MEDIUM 4.3 The WP-Polls plugin for WordPress is vulnerable to Race Condition in the function vote_poll_process() in versions up to,… wordfence
d19ac6fc-029f-4f19-913e-e082acecc594
< 2.2.5
MEDIUM 4.3 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
d18e9696-0f96-4478-9871-a93ac2976c11
< 3.11.15
MEDIUM 4.3 The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Missing Authorization in a… wordfence
d1898b09-695a-4767-9047-b0343e18a62e
< 1.6.2
MEDIUM 4.3 The Stratum Widgets for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
d16fa590-1409-4f04-b8b7-0cce17412a5f
< 1.7.2
MEDIUM 4.3 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
d1436ca4-933b-426a-987d-c5cbbc29353b
< 2.0.3
MEDIUM 4.3 The WooCommerce Pre-Orders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
d139fb44-b66b-46e3-af99-9404ec34fd06 MEDIUM 4.3 The OSS Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.… wordfence
d1390c22-3c8d-47f1-b225-1bcbc215832a MEDIUM 4.3 The Don't Muck My Markup plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
d132d587-0c90-40b2-97b7-c5f1d3dd3bac MEDIUM 4.3 The Elite Video Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
d1291a06-a596-4e87-9036-787039b06850 MEDIUM 4.3 The Flexible FAQ plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2.… wordfence
d105cae2-2442-4726-bbe8-2edbd1e7a28c
< 4.0.3
MEDIUM 4.3 The Media Hygiene: Remove or Delete Unused Images and More! plugin for WordPress is vulnerable to unauthorized access du… wordfence
d0f6d28a-d5ca-4700-bc61-f2dd20f06fcf
< 3.8.0
MEDIUM 4.3 The Groups plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, … wordfence
d0f5b9b7-2482-4f25-b50e-e2d9b3ef4902
< 0.2.5
MEDIUM 4.3 The SL User Create plugin for WordPress is vulnerable to Information Disclosure in versions before 0.2.5 due to a weak s… wordfence
← Prev 1385 1386 1387 1388 1389 1390 1391 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top