🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 20 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
dd75b8ec-1961-4a7a-92e6-1517e638974b CRITICAL 9.8 The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability chec… wordfence
dd5b0c3a-0dd0-440f-b3a5-6d80f70e0f7c
< 2.4.0
CRITICAL 9.8 The Zingiri Web Shop plugin for WordPress has multiple vulnerabilities in versions up to, and including, 2.3.7. This is … wordfence
dd58a528-4c01-407d-b3f9-99c0817e9820 CRITICAL 9.8 The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_to… wordfence
dd2d82f4-1493-4829-a4e9-adbb98301324 CRITICAL 9.8 The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL sta… wordfence
dcfd8c4d-d48b-468d-a7d5-1ec05b068f79 CRITICAL 9.8 The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, … wordfence
dcea4ecf-e690-4d1f-beab-fbb30c5bb52e
< 2.0.1
CRITICAL 9.8 An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers… wordfence
dc83b0ff-7228-466a-b831-53cca252a3f3
< 1.9.3
CRITICAL 9.8 PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress p… wordfence
dc7f5751-5c95-4105-b2a6-592d11d46ac6
< 2.2.1
CRITICAL 9.8 The CE21 Suite plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.0. T… wordfence
dc57d762-1e26-4980-ac82-ba35bf252ef8
< 1.1.0
CRITICAL 9.8 The Demo My WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1… wordfence
dc3555b6-9b5d-4fed-9d99-9f69f0566b99 CRITICAL 9.8 The Sudan Payment Gateway for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… wordfence
dc3457a5-3d5b-40dc-b9b1-e819187c4d99
< 1.40.1
CRITICAL 9.8 The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 d… wordfence
dc1e5fb7-92d0-4e7f-9b1b-15673e3b852a
< 2.7.4
CRITICAL 9.8 The Gravity Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.7.3 via… wordfence
dc02768c-3ea1-4254-a652-342d0abdf839
< 2.4.1
CRITICAL 9.8 The Dør theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4. This makes it … wordfence
dbfc52a4-6c9d-480b-9247-1513318ff84b CRITICAL 9.8 The Contact form 7 Custom validation plugin for WordPress is vulnerable toSQL Injection via the 'post' parameter in vers… wordfence
dbadc2e6-38fa-47f8-9d8b-79fb867f1003
< 5.6.0
CRITICAL 9.8 The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Privilege… wordfence
db9819c4-e000-4113-a613-7510fce923c9
< 8.1.7
CRITICAL 9.8 The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulner… wordfence
db7234a1-e888-454d-8a1c-4de19c4cbec4
< 2.0.1
CRITICAL 9.8 Multiple SQL injection vulnerabilities in the getip function in wp-limit-login-attempts.php in the WP Limit Login Attemp… wordfence
db30acd7-ce51-45d9-8ff0-6ceea8237a8c
< 2.1.33
CRITICAL 9.8 The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32… wordfence
db1c581b-5cc9-46c0-ba5d-605642697729 CRITICAL 9.8 The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up … wordfence
dac658b5-4253-4095-9fda-4d3cdc7f7e2e
< 0.4.2
CRITICAL 9.8 The CDN Vote plugin for WordPress is vulnerable to SQL Injection via the 'cdnvote_post_id' and 'cdnvote_point' parameter… wordfence
dabd12b9-c07d-4a5d-bec3-905b90ff0dbf CRITICAL 9.8 The Fontsy plugin for WordPress is vulnerable to SQL Injection via many parameters, such as 'id' called via get_fonts() … wordfence
dab7e451-f2ea-4f41-8e38-a2a983ccb18b
< 6.9
CRITICAL 9.8 The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra… wordfence
da95e282-54b9-4296-99f3-9187c04dcaac
< 1.5.8
CRITICAL 9.8 The Leaflet Maps Marker Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
da95086a-6ae2-4b4d-8312-78e3800ded7f
< 2015.0514
CRITICAL 9.8 SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for W… wordfence
da86d422-f0ef-439b-ae67-6cb9699073e0
< 3.0.18
CRITICAL 9.8 The Wawp OTP Verification, Order Notifications, and Country Code Selector for WooCommerce plugin for WordPress is vulner… wordfence
← Prev 17 18 19 20 21 22 23 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top