πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1389 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d0d78230-2722-40ff-a54d-0f1896ca3349
< 2.7.5
MEDIUM 4.3 The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized access due to a miss… wordfence
d0d6f467-6e62-45ff-bf9d-4db5b1ed1dd2
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability c… wordfence
d0cb4434-94c5-42a9-bd86-869058dcbf67
< 1.23.3
MEDIUM 4.3 The Forminator plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'hub… wordfence
d0ca76a3-143c-4e86-a6d7-e1d3b3d7b378 MEDIUM 4.3 The Nice PayPal Button Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
d0c91a58-31e9-4f6e-81fb-0681fb9ce4d6
< 4.5.5
MEDIUM 4.3 The WpStream – Live Streaming, Video on Demand, Pay Per View plugin for WordPress is vulnerable to Cross-Site Request … wordfence
d0c4b963-047a-4d41-8dba-9eaa5e555235
< 5.1.3
MEDIUM 4.3 The Widget Options - Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to… wordfence
d0af6050-8602-4ed3-b017-c10aa023849b
< 1.4.67
MEDIUM 4.3 The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modificati… wordfence
d0aa1fad-1ff4-4bc5-a584-99b528470990
< 2.0.7
MEDIUM 4.3 The WP Job Portal – A Complete Job Board plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… wordfence
d0969d4a-c1cd-4b60-b298-e97f694887e9
< 1.49.1
MEDIUM 4.3 The YITH PayPal Express Checkout for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… wordfence
d087957c-0dd5-46a9-a6bc-85f2f79f43bd
< 1.9.0
MEDIUM 4.3 The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to unauthorized access t… wordfence
d08282a5-8e16-4f54-9243-68f0af514c12 MEDIUM 4.3 The Image Slider Slideshow plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,… wordfence
d07d8c3a-5e97-422a-ba20-e0bc206dda59 MEDIUM 4.3 The Rus-To-Lat plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.3. T… wordfence
d073d9df-0636-4884-b5d0-e2da779e5edf
< 2.8.2
MEDIUM 4.3 The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Informatio… wordfence
d06f265c-c1c1-4316-9526-3392f6ee31da
< 1.0.4
MEDIUM 4.3 The Lock User Account plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
d06e9c13-a365-4dd7-a923-62ee2e2e2ffb
< 1.3.20
MEDIUM 4.3 The Premmerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.19.… wordfence
d0693b76-dd6a-4ebc-8384-b7dadb606849
< 8.4.6
MEDIUM 4.3 The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
d0631ec9-fb72-4573-a41b-9b6b01aeaae9
< 1.11.13
MEDIUM 4.3 The CartFlows Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1… wordfence
d04e87f3-351c-4352-a6f1-69c652baa992
< 1.7.0
MEDIUM 4.3 The Vertex Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
d03008ae-ccb5-43b2-834a-71c71c43c678
< 1.2.26
MEDIUM 4.3 The Fastly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on … wordfence
d02bc6c9-dca7-45cb-acc7-db0d269c16a3 MEDIUM 4.3 The Sidebar Manager Light plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
d00edaf1-2a97-4000-afd9-432ca8fa3df4
< 1.3.4.3
MEDIUM 4.3 The HUSKY – Products Filter for WooCommerce (formerly WOOF) plugin for WordPress is vulnerable to unauthorized access … wordfence
CVE-2026-8423 MEDIUM 4.3 The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… nvd
CVE-2026-3058 MEDIUM 4.3 The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … nvd
CVE-2026-3056 MEDIUM 4.3 The Seraphinite Accelerator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… nvd
CVE-2026-2633 MEDIUM 4.3 The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Missing Authorization in all versions u… nvd
← Prev 1386 1387 1388 1389 1390 1391 1392 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top