🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 281 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
dfa22747-b9f5-403e-81bb-87a593e603a4
< 2.2.22
HIGH 7.5 The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for W… wordfence
df75dd55-2af5-4615-9032-a4fcc90891b0 HIGH 7.5 The Popliup – WordPress Popup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,… wordfence
df53dea5-4497-45ee-8f5c-e43f19a702f9
< 2.3
HIGH 7.5 The mTheme-Unus theme for WordPress is vulnerable to Directory Traversal in versions up to 2.3 via the 'files' parameter… wordfence
df42202e-eb6d-487f-b394-fc278559ebe8
< 2.4
HIGH 7.5 The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to unauthorized access due to a miss… wordfence
df015a51-7eb8-4fbc-839f-bcf6b2e2b1a7
< 1.8.3
HIGH 7.5 The AccessPress Social Icons plugin for WordPress contains a backdoor when downloaded directly from the AccessPress site… wordfence
defd82dd-bda0-4f0c-88cb-4db983953097
< 3.3.0
HIGH 7.5 The Simple JWT Login WordPress plugin before 3.3.0 can be used to create new WordPress user accounts with a randomly gen… wordfence
deec46f4-f7b4-4da4-aa3a-d04b9177528f
< 7.4.1
HIGH 7.5 The wpDataTables (Premium) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.4 due… wordfence
dee61aa4-4c35-464e-b085-974e17e1eabb
< 5.2.0
HIGH 7.5 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to SQL Injection in versions up to,… wordfence
dec38992-a69f-4ccd-a23b-4dd1639897c3
< 1.5.1
HIGH 7.5 The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX fu… wordfence
de9272e9-8dda-4b69-86c0-2736941b8e27
< 7.0.1
HIGH 7.5 The WPJAM Basic plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 7.0 via des… wordfence
de754e7d-4ad4-49f3-b730-e81f6c5bc5f8
< 1.7.8
HIGH 7.5 The Calafate theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.7. This mak… wordfence
de74cf61-d15f-4d77-9c7e-950f48579d22
< 3.3.9.2
HIGH 7.5 The WordPress WP-Advanced-Search plugin for WordPress is vulnerable to SQL Injection in all versions up to, and includin… wordfence
de1bcbea-5539-456f-94dc-c70fb7acc455
< 4.22.0
HIGH 7.5 The kallyas theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.21.0 via t… wordfence
dcef742e-2f1a-4bb3-a613-69b743b1e544 HIGH 7.5 The Wishlist Member plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.29.0 … wordfence
dce76d59-e798-4762-8247-eddebd38c165
< 1.5.0
HIGH 7.5 The WP Edit Menu plugin for WordPress lacks authorization checks on one of its ajax action and is vulnerable to Arbitrar… wordfence
dc7d0124-9ddd-4f88-bffd-e09e10137a3d
< 1.5.7
HIGH 7.5 Multiple cross-site request forgery (CSRF) vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SE… wordfence
dc676e18-c895-4f6a-bce9-1f92207af885
< 3.4.1
HIGH 7.5 The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions… wordfence
dc4883b8-5783-49ff-ab3b-c568c9923227
< 3.6.33
HIGH 7.5 The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all ve… wordfence
dc37b864-f1a5-4963-9efc-d9bb88a7a43a HIGH 7.5 The MelAbu WP Download Counter Button plugin for WordPress is vulnerable to Arbitrary File Download in all versions up t… wordfence
dc07bcec-f822-492a-b73d-79e791907dd1 HIGH 7.5 The Easy Forms for Mailchimp plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,… wordfence
dbe0cc57-a17d-4f91-887f-fe819b32f6b3
< 5.0.3
HIGH 7.5 The Responsive theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
db9cd10e-90c1-48b2-8760-d5fc501fb3ba
< 3.0.0
HIGH 7.5 The Javo Spot theme for WordPress is vulnerable to Directory Traversal in versions up to 3.0.0 via the 'fn' parameter fo… wordfence
db3bddbd-44b0-4105-9039-0d669d643481
< 1.6.11.9
HIGH 7.5 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to t… wordfence
db3594df-8f24-4e24-b960-b13e5bca966e
< 2.5
HIGH 7.5 The Modular Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.4. This is … wordfence
db2b8c8d-2507-4325-ab65-ca71ba8da21f
< v10.9.4
HIGH 7.5 The Wp EMember plugin for WordPress is vulnerable to SQL Injection in versions up to v10.9.4 due to insufficient escapin… wordfence
← Prev 278 279 280 281 282 283 284 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top