πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 349 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
dd389d3b-046c-41cb-a077-7dcb9fd50eda
< 14.16.7
HIGH 7.2 The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored… wordfence
dcf54e27-e2d1-4d87-8eb6-2881054b70fe
< 1.5.8
HIGH 7.2 The Fluent Support plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and i… wordfence
dcf38298-9ccf-4939-b764-f83dbca4d54e
< 1.3.2
HIGH 7.2 The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
dc9676ef-34d7-4a88-a295-1c7136a0e6cd HIGH 7.2 The Dextaz Ping plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.65. … wordfence
dc8b33c7-23ef-4b5c-bdb9-b4e548d18832
< 2.10.4
HIGH 7.2 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… wordfence
dc5276e2-e9de-4409-bbe0-4d0b37244367
< 4.9.51
HIGH 7.2 The WooCommerce Follow-Up Emails plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4… wordfence
dc4a6c2a-9a16-47dc-97ea-914adfb34688
< 2.1.1
HIGH 7.2 The MelaPress Login Security plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… wordfence
dc2532b4-907f-438b-baab-c3966cf30f74
< 1.8.0
HIGH 7.2 The Student Results or Employee Database plugin for WordPress is vulnerable to unauthorized REST calls in versions up to… wordfence
dbf2b1a9-c248-4b77-a90d-4d3b5cfc447c HIGH 7.2 The WP Real IP-based Access Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
db701ad3-10fd-4a40-b239-139fbc95ab61
< 1.8.0
HIGH 7.2 The Rich Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the POST body 'update' parameter i… wordfence
db6f08f9-4da3-450d-bf1e-5c9f0aab02a1
< 4.9.32
HIGH 7.2 The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'MWP-Key-Name' HTTP reques… wordfence
db484c8a-e46d-457b-b634-28d823ff2120
< 3.0.2
HIGH 7.2 Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high pr… wordfence
db3d9cd4-e7d8-4aab-bbaf-83473c70af40
< 3.6.33
HIGH 7.2 The My auctions allegro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
db1bb11d-4752-42d0-b538-2d2a4c827226
< 4.7.9
HIGH 7.2 The AI ChatBot plugin for WordPress is vulnerable to SQL Injection via the orderby parameter in all versions up to, and … wordfence
dadfa92b-c674-4523-89b9-e8817e521c17
< 5.7.3
HIGH 7.2 The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for Wor… wordfence
dad27b29-d106-44f2-9b88-6cce0c0cf4a5
< 4.3.45
HIGH 7.2 The WPtouch plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation when upload… wordfence
dab0ddfb-6e30-4bde-95fb-90570579ff04
< 2.0.2
HIGH 7.2 Multiple cross-site scripting (XSS) vulnerabilities in the "post comment" functionality of WordPress 2.0.1 and earlier a… wordfence
da848ced-acc4-48bc-8fbe-e90cdd53b3e8
< 20160215
HIGH 7.2 The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field. wordfence
da8166f3-02d8-4519-a518-0f5e9e1b1ab3
< 2.97.4
HIGH 7.2 The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
da235dea-4884-4e6a-a8b8-65d34f050684
< 9.2.3
HIGH 7.2 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
d9f6b761-9c4b-4dcc-885d-9a5b4e8e534d
< 2.5.1
HIGH 7.2 The AI Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 vi… wordfence
d97c3379-56c9-4261-9a70-3119ec121a40
< 7.87
HIGH 7.2 The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing… wordfence
d969fb35-2ee9-42ca-a9e8-f6453a1e6be9
< 3.3.6
HIGH 7.2 The Companion Auto Update plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.3.5 du… wordfence
d9244775-eab8-4cf4-98bb-97e467dcc5cf
< 5.3
HIGH 7.2 The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection. wordfence
d91cd902-f429-4b13-a0d0-04af8f908c95
< 3.1.58
HIGH 7.2 The Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
← Prev 346 347 348 349 350 351 352 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top