🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1001 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1122313e-7dcd-4b21-b382-898e5168e5d3 MEDIUM 6.1 The WP Cards plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … wordfence
11177270-cc73-4c65-9f72-8c0a0a89bed5
< 3.1.2
MEDIUM 6.1 The 404 to 301 – Redirect, Log and Notify 404 Errors plugin for WordPress is vulnerable to Reflected Cross-Site Script… wordfence
110c6d41-e814-41c9-a3e7-d94ec3d953e6
< 2.0.4
MEDIUM 6.1 The Star CloudPRNT for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'printer… wordfence
10fcfddf-0ed7-471d-86bf-c38e7021c6a4
< 1.0.3
MEDIUM 6.1 The Clio Grow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg witho… wordfence
10c8dc50-2c69-4c9d-a546-8ffcfcbb6ee1 MEDIUM 6.1 The Management-screen-droptiles plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
10c41b59-c83e-4f72-8b20-10db731e23c2
< 4.6.1
MEDIUM 6.1 The eelv-newsletter plugin before 4.6.1 for WordPress has XSS in the address book. wordfence
10b46c11-1b34-4da4-a24d-103c663ca315
< 3.2.60
MEDIUM 6.1 The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘packages-shortcode-… wordfence
10b3256b-5271-44b8-ab4d-05156d4f674b
< 2.1.3
MEDIUM 6.1 The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the… wordfence
10ac9e80-7aa9-4cc5-ad37-f15f8d12ed16
< 2.1
MEDIUM 6.1 The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php via the status parameter. This makes it possible… wordfence
10ab67ed-2660-4c4d-8aeb-688b5fec1c1e MEDIUM 6.1 The Random Image Selector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
1096177a-a816-4ce6-9dec-4232b1e121e7 MEDIUM 6.1 The WordPress Additional Logins plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up … wordfence
108a2ea3-a612-46a2-b29a-7ae794f8470c
< 2015.0514
MEDIUM 6.1 The feedwordpress plugin before 2015.0514 for WordPress has XSS via add_query_arg() and remove_query_arg(). wordfence
1087f744-44c2-4fa1-92d9-872a5bfd571d
< 1.18.3
MEDIUM 6.1 Insufficient Input Validation in the search functionality of Wordpress plugin Use-Your-Drive prior to 1.18.3 allows unau… wordfence
10818590-6412-458f-a473-b24dc0b293dd MEDIUM 6.1 The GamePress WordPress plugin through 1.1.0 does not escape the op_edit POST parameter before outputting it back in mul… wordfence
107918e4-fb21-40df-818d-a71b78b26928
< 2.9.15
MEDIUM 6.1 The Sunshine Photo Cart plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' param… wordfence
10786490-9032-41c2-9353-aacf9ea3e229 MEDIUM 6.1 The Pesapal Gateway for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up … wordfence
1074115c-31eb-4276-915b-7fc8b17239d7 MEDIUM 6.1 The CubePM plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.… wordfence
1071a052-4c76-45cb-acf5-c7ae90acfc63 MEDIUM 6.1 The UberSlider Classic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
10685fdc-fe13-44a4-9058-57b57905a24d
< 1.6.9
MEDIUM 6.1 The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress is vulnerable to Reflected … wordfence
106451c1-e0e7-4318-ac27-e17943874a8f MEDIUM 6.1 The Rio Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
103ce24e-1c21-4c25-b3d0-6f595bf58979
< 1.8.3
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remot… wordfence
1034f0f4-52e4-4f4c-81fc-51b4720f306a
< 6.4.5
MEDIUM 6.1 The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
10339a77-7c1a-4030-9061-15c699545b16
< 1.0.8.1
MEDIUM 6.1 The WOLF plugin for WordPress is vulnerable to stored Cross-Site Scripting via the ‘profile_title’ parameter in vers… wordfence
1032f7b0-db98-4b25-bdff-dcaf2758f266
< 4.8.84
MEDIUM 6.1 Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML … wordfence
1032227b-f2bc-4fc5-bc8d-91a84c631680
< 1.98
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in paginas/vista-previa-form.php in the EnvialoSimple: Email Marketi… wordfence
← Prev 998 999 1000 1001 1002 1003 1004 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top