πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 759 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d7aceccc-7004-42f2-b085-eade9c45141c
< 5.3.15
MEDIUM 6.3 The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
d767b710-0bef-4f36-8edd-eccd845a2b07 MEDIUM 6.3 Cross-site request forgery (CSRF) vulnerability in the Content Slide plugin 1.4.2 for WordPress allows remote attackers … wordfence
d5502ebc-0b35-4966-bff6-90efdcb0db58
< 1.14.14
MEDIUM 6.3 The MultiParcels Shipping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
d3ee6004-03d1-4216-b22e-0aadc1f4d9de
< 4.3.8
MEDIUM 6.3 The RealHomes theme for WordPress is vulnerable to unauthorized access due to a missing capability check an unknown func… wordfence
d35ff2cc-9af2-4b72-bc49-e205275daa4d
< 3.8.1
MEDIUM 6.3 The Spreadsheet Integration – Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Di… wordfence
d3004699-3285-426a-8a85-33be6c0c0b6f
< 3.15.9
MEDIUM 6.3 The Print My Blog – Print, PDF, & eBook Converter plugin for WordPress is vulnerable to authorization bypass due to mi… wordfence
d2b4203f-7301-4ab6-b7a1-c43516bea477 MEDIUM 6.3 The Football Live Scores plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on … wordfence
d29d27f5-d2fd-4124-bb94-dc5baf37d0a7
< 5.3.1
MEDIUM 6.3 The The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to arbitrary shortcode execu… wordfence
d293f35a-a42f-441f-b521-da0ba9887c45
< 1.8.2
MEDIUM 6.3 The HappyFiles Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of … wordfence
d26e8b21-fa9e-4dfe-a095-5c9f74d968f4
< 9.7.5
MEDIUM 6.3 The Quick Event Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
d242a466-0611-4e64-8145-29f64100e62b
< 3.7.0
MEDIUM 6.3 The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to unauthorized access and modifi… wordfence
d1568e8d-9ea5-4673-a657-03e89cfb6000 MEDIUM 6.3 The Remote Content Shortcode plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… wordfence
d12c4b1c-23d0-430f-a6ea-0a3ab487ed10 MEDIUM 6.3 The WP Easy Post Types plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to … wordfence
d0e02954-a2e7-417b-a467-fee0076d9b2a MEDIUM 6.3 The User Meta Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
cdf67099-5514-45ba-9a4c-10af984bf593
< 3.0.0.2905
MEDIUM 6.3 The Rover IDX plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing… wordfence
cd88b116-0a6e-412b-8d43-024fdf36bcdf
< 1.7.1
MEDIUM 6.3 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to authorization bypass in versions up … wordfence
cd4dc8ab-792b-41ff-a7b9-77a11c02d91b MEDIUM 6.3 The Inpersttion For Theme plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi… wordfence
ccb81a3e-744f-4a16-ad9b-1b9dbc09571c MEDIUM 6.3 The Schema Plugin For Divi, Gutenberg & Shortcodes plugin for WordPress is vulnerable to Object Instantiation in all ver… wordfence
cc912ace-65d9-4833-a3ad-dc5d37989269
< 1.8.12
MEDIUM 6.3 The TrustMate.io integration for WooCommerce plugin for WordPress is vulnerable to Blog Option Update via the 'save_chec… wordfence
c7f7e545-5e14-421e-90b4-bc54b23d0fe6 MEDIUM 6.3 The WPS Telegram Chat plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a … wordfence
c20e288e-492d-49ed-89cb-e1ee3e8c204e MEDIUM 6.3 Cross-site request forgery (CSRF) vulnerability in the Twitter LiveBlog plugin 1.1.2 and earlier for WordPress allows re… wordfence
c0a61e11-1137-4da0-8580-0a44300b1542
< 2.9.1.7
MEDIUM 6.3 The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including… wordfence
bbb57de9-210e-4983-965b-9a74ca10c494
< 2.5.0
MEDIUM 6.3 The Contact Form Generator : Creative form builder for WordPress for WordPress is vulnerable to Cross-Site Request Forge… wordfence
b950faf9-2122-42af-9f05-ec850767be32
< 4.2.5
MEDIUM 6.3 The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Cro… wordfence
b808450f-0ebf-4c49-a9e3-f1c1f2b1f632
< 3.7.1
MEDIUM 6.3 The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Cross-Site Request Forgery due… wordfence
← Prev 756 757 758 759 760 761 762 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top