ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 804 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
da4684b8-20f6-4dc1-8f29-d79f64ccb9d8
< 4.1.0
MEDIUM 6.1 The Contractor Contact Form Website to Workflow Tool plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
da18dce3-f8f9-48ae-b767-0b72ffd75c1e
< 2.0.7
MEDIUM 6.1 The WordPress Helpdesk & Live Chat Plugin Powered by AI – ThriveDesk plugin for WordPress is vulnerable to Reflected C… wordfence
da125e31-4747-46b7-8a46-a234388035c0 MEDIUM 6.1 The Enable Accessibility plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_quer… wordfence
d9fbedea-15e7-4233-8e2d-9fd928fe4f2a
< 0.0.22
MEDIUM 6.1 The Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS plugin for WordPress is … wordfence
d9f9d20f-a0cd-40ed-8f75-7b57fe8e70f0 MEDIUM 6.1 The 多说社会化评论框 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
d9e77e3f-dcd8-426a-be0f-24eb65c6709e
< 3.2
MEDIUM 6.1 The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via… wordfence
d9e3f310-5a5e-4ca8-806d-9a7aacfaf5ed
< 4.6.1
MEDIUM 6.1 The Search Forms page of the Ivory Search WordPress lugin before 4.6.1 did not properly sanitise the tab parameter befor… wordfence
d9e0f3a5-35fb-4c7e-892f-8a41498e1d3c MEDIUM 6.1 The Visit Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missin… wordfence
d9d19571-f0a1-4f15-a292-89b938c49afc
< 1.1.17
MEDIUM 6.1 The Travelpayouts: All Travel Brands in One Place plugin for WordPress is vulnerable to Open Redirect in versions 0.0.0.… wordfence
d9c20584-d791-4788-8dc3-77069b92601f
< 1.3.02
MEDIUM 6.1 The "CP Contact Form with PayPal" plugin before 1.3.02 for WordPress has XSS in CSS edition. wordfence
d9bfae23-7b5c-46d8-9d7e-cc261280e223
< 1.2.0
MEDIUM 6.1 The login-or-logout-menu-item plugin before 1.2.0 for WordPress has no requirement for lolmi_save_settings authenticatio… wordfence
d9ae6150-209b-4717-835a-e5d5ea62a19b MEDIUM 6.1 The Ofiz theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.0 d… wordfence
d9a7f2ed-b2c0-4042-ad91-63070e176c2f
< 1.4.0
MEDIUM 6.1 The Agrofood theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and excluding, 1.4.0… wordfence
d9a70e02-fdbc-43ee-9382-101391f363a3
< 4.20.94
MEDIUM 6.1 The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST… wordfence
d99fe68c-3c0e-4a5a-96c8-de50b7a7e753 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in inpage.tpl.php in the Keyword Strategy Internal Links plugin 2.0 and earlier… wordfence
d99a545f-e4eb-4130-8b1c-bb485c1aad13 MEDIUM 6.1 The bidorbuy Store Integrator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
d992a9cf-f24c-4c82-a56b-22394524ba3b
< 1.2.9.3
MEDIUM 6.1 The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter bef… wordfence
d9853616-e1b3-48b0-afec-c43e91c48bc0 MEDIUM 6.1 The Fontsampler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0… wordfence
d97df193-28ed-4961-9d71-00098c0bec45
< 3.4.24.2
MEDIUM 6.1 The Ninja Forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS. wordfence
d96d1f33-43b3-4e20-967e-988cb32b04ee MEDIUM 6.1 The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
d94c0775-3852-463f-b393-1a12e63548e0
< 1.2.6.3
MEDIUM 6.1 The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in … wordfence
d94bcbf7-c20e-4b04-b4de-f68f9a793b73
< 6.2.2
MEDIUM 6.1 The Quiz And Survey Master plugin 6.2.1 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS. wordfence
d941b4b7-6b61-4559-8980-ae7285018b98
< 2.1.5
MEDIUM 6.1 The ABA PayWay Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in v… wordfence
d92caa38-6a0e-46e7-87db-b5c7d325d138
< 2.0
MEDIUM 6.1 The SKT Donation – Charity and Fundraising Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
d91a2713-238b-4c56-bff8-9129d77f4d77
< 3.9.5
MEDIUM 6.1 The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm… wordfence
← Prev 801 802 803 804 805 806 807 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top