🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1000 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
12263ca7-41d8-4ef2-b644-ddfcae8c9665
< 3.4.8
MEDIUM 6.1 The Brafton plugin before 3.4.8 for WordPress has XSS via the wp-admin/admin.php?page=BraftonArticleLoader tab parameter… wordfence
121c8bcd-ebfd-4e2f-8417-836db846b5a4
< 6.3.9
MEDIUM 6.1 The Simple File List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
12081e8c-7aec-4450-a1a6-15250e7037f4
< 1.86
MEDIUM 6.1 The Debug Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.8… wordfence
11ccafd9-dad5-4b7d-b913-7821dd52d12b
< 2.4.3
MEDIUM 6.1 The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Reflected Cross… wordfence
11c7b2a8-33fd-4dc4-8373-09f672053b8c MEDIUM 6.1 The Easy Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
11c7abc5-1a41-4eab-b603-064baf978ddd
< 1.5.8
MEDIUM 6.1 The Leaflet Maps Marker Pro plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including,… wordfence
11aec50c-2531-4d30-92da-8513fdca741e
< 5.5.7
MEDIUM 6.1 The Checkout Fields Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ver… wordfence
11ad65cd-941f-4605-8b69-59146b2d59db
< 4.3
MEDIUM 6.1 The SEO Redirection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versio… wordfence
11aa7971-9770-47fc-960e-44fe43321b53 MEDIUM 6.1 The Calendar_plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of `$_SERVER['PHP_SE… wordfence
11a3d6e1-d158-45a9-b3c0-c496ce86b3ef MEDIUM 6.1 The Notifikácie.sk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
119f87d0-dcd7-487a-bee5-ebcfbcb0a62a MEDIUM 6.1 The Music Request Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
11938a57-3eb7-4e7d-99ae-c6cf508cb4c7
< 1.8.22
MEDIUM 6.1 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
118b9d85-1246-47f7-bdef-af47075576f2
< 1.2.12
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in view/frontend-head.php in the Flowplayer plugin before 1.2.12 for WordPress … wordfence
116f9dad-24be-4156-932e-742fa9a4919e MEDIUM 6.1 The Meta Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
116a9d87-e271-4f7b-a509-63d4a172f1db MEDIUM 6.1 The Uji Countdown plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
116593ea-7fbb-45c7-aa34-0b6d8f7cc0e2 MEDIUM 6.1 The leenk.me plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.16… wordfence
115ad0b2-febe-485a-8fb5-9bd6edc37ef7
< 2.2.3
MEDIUM 6.1 The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in versions up … wordfence
1153eef6-f220-4f96-bf82-fb54496c6582 MEDIUM 6.1 The Woocommerce osCommerce Sync plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to,… wordfence
113d3dfe-02f7-455e-a4e1-2bea2dec93f3
< 1.9.2
MEDIUM 6.1 The AdminQuickbar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
113287e2-0d8e-4109-ab24-ba2283cc9964 MEDIUM 6.1 The GravatarLocalCache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
112cea93-fa4b-4692-8c8b-e74255f61939
< 4.2.4
MEDIUM 6.1 The Optimole – Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via U… wordfence
11296672-cbf3-4b2c-a871-abff487f20f5 MEDIUM 6.1 The ACF: Google Font Selector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… wordfence
11280431-ee39-45da-909a-e9efc0e6266f
< 7.4.2
MEDIUM 6.1 The Avada theme for WordPress is vulnerable to Reflected Cross-Site Scripting via improper escaping of bbPress searches … wordfence
1127a5f3-1698-45e9-85bd-4eebfdbe56d4
< 2.7.4
MEDIUM 6.1 The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
112564b7-bf3c-4c17-8113-e05ab75edf6a
< 1.5.3
MEDIUM 6.1 wordfence
← Prev 997 998 999 1000 1001 1002 1003 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top