πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 436 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
de6da87e-8f7d-4120-8a1b-390ef7733d84
< 2.8.02
MEDIUM 6.5 The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of d… wordfence
de3cf63f-ac30-47bb-978d-d3353d06de1b MEDIUM 6.5 The Post Slider plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the togg… wordfence
de39bad4-858a-4332-8ed0-bfd92a67b9cb
< 5.0.8
MEDIUM 6.5 The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to IP Address Spoofing in ve… wordfence
de11c9ad-0b9f-4934-8dc9-dc324d77d702
< 3.7.24
MEDIUM 6.5 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure… wordfence
dd7c3a5d-b8aa-45cb-983c-55ba7e3d72f3
< 3.1.0
MEDIUM 6.5 The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versi… wordfence
dd7b72bb-2cf7-4a8d-b323-66c94b500cb0
< 5.7
MEDIUM 6.5 The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check author… wordfence
dd6becbf-29cc-4744-8c9b-5b75f8c5f402
< 1.5.0.5
MEDIUM 6.5 The Tipsacarrier WordPress plugin through 1.5.0.5 (not included) does not have any authorisation check in place in some … wordfence
dcd463de-ae26-4477-89e1-21f4aada1e86 MEDIUM 6.5 The BuddyPress Xprofile Custom Fields Type plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up … wordfence
dcbc0ceb-7e23-4475-a138-25dc15ec17f7
< 1.0.12
MEDIUM 6.5 The Yes/No Chart WordPress plugin before 1.0.12 did not sanitise its sid shortcode parameter before using it in a SQL st… wordfence
dbfa20ad-6411-4054-9973-cb12d17c57f6
< 2.0.6.1
MEDIUM 6.5 The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and incl… wordfence
db5d4a3d-3ef6-4d91-b047-df377792958d
< 14.8.1
MEDIUM 6.5 The Simple Link Directory plugin for WordPress is vulnerable to SQL Injection in versions up to, and excluding, 14.8.1 d… wordfence
db5305e6-46b9-41a9-a54b-0b8e0d56df72
< 2.8.6
MEDIUM 6.5 The Lobo theme for WordPress is vulnerable to SQL Injection in versions up to 2.8.6 due to insufficient escaping on the … wordfence
d9f060bd-029a-462e-b308-8366e82be383
< 6.3.1
MEDIUM 6.5 The Formidable Forms plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due… wordfence
d9bebdc0-1625-4dc4-8c92-37f379868cd5
< 3.41.0
MEDIUM 6.5 The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based S… wordfence
d9b1044d-6858-498f-9b89-352650061858
< 5.3.15
MEDIUM 6.5 The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing… wordfence
d969eb46-b12a-4a36-9321-bf1479906a5d
< 3.6.3
MEDIUM 6.5 The WPFunnels plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in … wordfence
d95fe9e6-88cb-4dcb-9bf0-b71a180d5310
< 1.3.5
MEDIUM 6.5 The Appsero Helper plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.4 due to in… wordfence
d8dc995d-912e-4d83-84cc-c99242022b82
< 5.9.17
MEDIUM 6.5 The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the 'workflow_ids' para… wordfence
d8d50b65-7479-4140-9231-c06c18d8be8f
< 1.0.37
MEDIUM 6.5 The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorize… wordfence
d8aa06eb-774a-4cd9-bd35-2d6409475696 MEDIUM 6.5 The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi… wordfence
d8680df5-ef0c-45b6-b2c7-c54e60176bd6
< 3.3.0
MEDIUM 6.5 The Web3Press – Decentralize Publishing with Writing NFT plugin for WordPress is vulnerable to Directory Traversal in … wordfence
d8451f0f-0dfd-4926-aa35-75edf70ed6f2
< 2.2.20.1
MEDIUM 6.5 The Permalink Manager Lite plugin for WordPress is vulnerable to authorization bypass due to a missing capability check … wordfence
d7f59489-9bff-4d22-8f99-6ea52d702ecf
< 5.3.2
MEDIUM 6.5 The The Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro plugin for WordPress for WordPress is vulnerab… wordfence
d7ce047b-3cd3-475b-9a9f-38d15174e7e5
< 1.7.1060
MEDIUM 6.5 The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrar… wordfence
d7b8d42c-bceb-456e-a682-358e8df831e3
< 1.53.0.1
MEDIUM 6.5 The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0.… wordfence
← Prev 433 434 435 436 437 438 439 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top