🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1005 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0dd1706c-fb3b-4a5d-947a-435954eb0b15
< 3.13
MEDIUM 6.1 The Add Hierarchy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
0dbaf893-e117-448f-a1b3-9c4b4caea7e7 MEDIUM 6.1 The Import CSV Files plugin for WordPress is vulnerable to Reflected Cross-Site Scripting through imported content in ve… wordfence
0db59761-fbce-475e-aa76-c9d589b335eb MEDIUM 6.1 The Daily Image plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
0db32d66-4def-4356-96d8-74ba49e7604a
< 1.2.0
MEDIUM 6.1 The Social Ring (Facebook Like, Google +1, ReTweet, LinkedIn and Pin It) plugin for WordPress is vulnerable to Reflected… wordfence
0d9077cf-10cc-47cd-aca8-8f2110ccc407
< 1.25.3
MEDIUM 6.1 The Name Directory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘name’ parameter in … wordfence
0d7fec5d-895e-4366-a31c-248a3daf8937
< 1.7.22
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in adminimize/adminimize_page.php in the Adminimize plugin before 1.7.22 for Wo… wordfence
0d6f500c-3fad-4394-b8a3-0c128d0d57f4 MEDIUM 6.1 The CalendApp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
0d6914fa-d968-44c0-be88-b3e8c8d3ebf1 MEDIUM 6.1 The Custom Comment Notifications plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
0d594e40-ae4d-43f7-b57e-8070a68d1c94
< 3.0.2
MEDIUM 6.1 The WP Cleanfix plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up … wordfence
0d50eda3-20d8-436b-968c-9d8eeccaa0c9 MEDIUM 6.1 The Sparky theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and output e… wordfence
0d443d5f-ccf7-4eed-a5cb-ead0466a9d42 MEDIUM 6.1 Reflected XSS in wordpress plugin simpel-reserveren v3.5.2 via page parameter. wordfence
0d40c05d-dc30-47b1-aea5-cd2b72d4c4c0
< 2.8.16
MEDIUM 6.1 The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via UR… wordfence
0d2daa67-50b6-4850-92bf-49f29b1d8eb7
< 2.0.1
MEDIUM 6.1 The trust-form plugin 2.0 for WordPress has XSS via the wp-admin/admin.php?page=trust-form-edit page parameter. wordfence
0d2309cd-625e-4508-8d60-25817023aa15
< 0.8.7
MEDIUM 6.1 Cross-site scripting vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to inject arbitrar… wordfence
0d1a12b9-ac2e-4c60-8dd5-484944bb0ab8
< 1.2
MEDIUM 6.1 The Custom Permalinks plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1 d… wordfence
0cff5ca7-887b-4d4d-8592-e40876fbe000 MEDIUM 6.1 The Insert HTML Here plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
0cee3379-7f53-408b-a77d-8eb69cbf3f63 MEDIUM 6.1 The Bulk Categories Assign plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
0ced1c79-97fe-4841-9a02-ffb9f336212a
< 2.7.30
MEDIUM 6.1 The SysBasics Customize My Account for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
0ce75db8-cf80-4d97-833b-1cb70f0eb93b MEDIUM 6.1 The SUPER RESPONSIVE SLIDER plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
0ce2dc45-0e23-4fba-8ef3-543db2a02eda
< 0.5.73
MEDIUM 6.1 The Co-marquage service-public.fr plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search… wordfence
0cd63268-49ed-43cc-9b91-ad2840220768 MEDIUM 6.1 The Scroll rss excerpt plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
0cca8b75-c4f5-47ef-90a1-c1270e2f37c1 MEDIUM 6.1 The WordPress Brute Force Protection – Stop Brute Force Attacks plugin for WordPress is vulnerable to Reflected Cross-… wordfence
0cbbfe17-4ca1-4f95-9bad-a5111a233872 MEDIUM 6.1 The ECT Social Share plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
0cae2bb8-33e7-47b0-861d-b976a67660ae MEDIUM 6.1 The Blue Triad EZAnalytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'bt_webid' param… wordfence
0c9687fc-ee21-45c3-a655-da1dd1bf7b2e MEDIUM 6.1 The My Reservation System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'val' parameter i… wordfence
← Prev 1002 1003 1004 1005 1006 1007 1008 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top