Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1389 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d0d78230-2722-40ff-a54d-0f1896ca3349 | < 2.7.5 |
MEDIUM | 4.3 | The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized access due to a miss… | — | wordfence |
| d0d6f467-6e62-45ff-bf9d-4db5b1ed1dd2 | < 1.1.4 |
MEDIUM | 4.3 | The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability c… | — | wordfence |
| d0cb4434-94c5-42a9-bd86-869058dcbf67 | < 1.23.3 |
MEDIUM | 4.3 | The Forminator plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'hub… | — | wordfence |
| d0ca76a3-143c-4e86-a6d7-e1d3b3d7b378 | MEDIUM | 4.3 | The Nice PayPal Button Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence | |
| d0c91a58-31e9-4f6e-81fb-0681fb9ce4d6 | < 4.5.5 |
MEDIUM | 4.3 | The WpStream β Live Streaming, Video on Demand, Pay Per View plugin for WordPress is vulnerable to Cross-Site Request … | — | wordfence |
| d0c4b963-047a-4d41-8dba-9eaa5e555235 | < 5.1.3 |
MEDIUM | 4.3 | The Widget Options - Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to… | — | wordfence |
| d0af6050-8602-4ed3-b017-c10aa023849b | < 1.4.67 |
MEDIUM | 4.3 | The Motors β Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modificati… | — | wordfence |
| d0aa1fad-1ff4-4bc5-a584-99b528470990 | < 2.0.7 |
MEDIUM | 4.3 | The WP Job Portal β A Complete Job Board plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… | — | wordfence |
| d0969d4a-c1cd-4b60-b298-e97f694887e9 | < 1.49.1 |
MEDIUM | 4.3 | The YITH PayPal Express Checkout for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… | — | wordfence |
| d087957c-0dd5-46a9-a6bc-85f2f79f43bd | < 1.9.0 |
MEDIUM | 4.3 | The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to unauthorized access t… | — | wordfence |
| d08282a5-8e16-4f54-9243-68f0af514c12 | MEDIUM | 4.3 | The Image Slider Slideshow plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,… | — | wordfence | |
| d07d8c3a-5e97-422a-ba20-e0bc206dda59 | MEDIUM | 4.3 | The Rus-To-Lat plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.3. T… | — | wordfence | |
| d073d9df-0636-4884-b5d0-e2da779e5edf | < 2.8.2 |
MEDIUM | 4.3 | The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Informatio… | — | wordfence |
| d06f265c-c1c1-4316-9526-3392f6ee31da | < 1.0.4 |
MEDIUM | 4.3 | The Lock User Account plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
| d06e9c13-a365-4dd7-a923-62ee2e2e2ffb | < 1.3.20 |
MEDIUM | 4.3 | The Premmerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.19.… | — | wordfence |
| d0693b76-dd6a-4ebc-8384-b7dadb606849 | < 8.4.6 |
MEDIUM | 4.3 | The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capab… | — | wordfence |
| d0631ec9-fb72-4573-a41b-9b6b01aeaae9 | < 1.11.13 |
MEDIUM | 4.3 | The CartFlows Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1… | — | wordfence |
| d04e87f3-351c-4352-a6f1-69c652baa992 | < 1.7.0 |
MEDIUM | 4.3 | The Vertex Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… | — | wordfence |
| d03008ae-ccb5-43b2-834a-71c71c43c678 | < 1.2.26 |
MEDIUM | 4.3 | The Fastly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on … | — | wordfence |
| d02bc6c9-dca7-45cb-acc7-db0d269c16a3 | MEDIUM | 4.3 | The Sidebar Manager Light plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | wordfence | |
| d00edaf1-2a97-4000-afd9-432ca8fa3df4 | < 1.3.4.3 |
MEDIUM | 4.3 | The HUSKY β Products Filter for WooCommerce (formerly WOOF) plugin for WordPress is vulnerable to unauthorized access … | — | wordfence |
| CVE-2026-8423 | MEDIUM | 4.3 | The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… | — | nvd | |
| CVE-2026-3058 | MEDIUM | 4.3 | The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … | — | nvd | |
| CVE-2026-3056 | MEDIUM | 4.3 | The Seraphinite Accelerator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… | — | nvd | |
| CVE-2026-2633 | MEDIUM | 4.3 | The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Missing Authorization in all versions u… | — | nvd |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →