🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1006 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0c824844-8095-45ac-b202-8ab368198dc4 MEDIUM 6.1 The electrician theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5… wordfence
0c7b4263-0c7b-4a1a-b168-88e6591c82bb MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in client-assist.php in the dsSearchAgent: WordPress Edition plugin 1.0-beta10 … wordfence
0c799ee5-d8ee-4aec-b9a5-f93c150de6bd MEDIUM 6.1 The BigBlueButton plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the username and temp_entry_p… wordfence
0c714138-1224-4966-8191-64a99505b8e8 MEDIUM 6.1 The Widgetize Pages Light plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
0c70206d-5c4a-4068-8182-e93378c26350 MEDIUM 6.1 The Custom Menu Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the selected_menu parameter … wordfence
0c6f44ba-a8c1-4248-8f54-ee86d4b5aa20
< 2.0.7
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.… wordfence
0c5b48a9-b9cc-4d8e-8ceb-5a816328d71e
< 1.2.3
MEDIUM 6.1 The Realtyna Provisioning plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
0c54bbfe-f505-4c93-89fb-1a624bfcfe10
< 1.92
MEDIUM 6.1 The WP Construction Mode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘set_opt’ para… wordfence
0c50e839-79c8-40c4-b2c4-b168e8537bfa MEDIUM 6.1 The Quote Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
0c4e0d48-fde1-45dd-8e06-4582cf677579
< 4.6.1
MEDIUM 6.1 The Login by Auth0 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wle’ parameter in a… wordfence
0c4d2829-9f99-4a2d-9bde-476fae2c99a4
< 2.2.9
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plu… wordfence
0c34d49a-0009-4856-9edb-517e2bf50d00 MEDIUM 6.1 The LambertGroup - AllInOne - Banner with Thumbnails plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
0c2c5b41-bc56-428f-9edc-2a8fd8212310
< 3.0
MEDIUM 6.1 The Wise Agent Capture Forms WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVE… wordfence
0c1ebc88-0987-46d6-9e80-6f3aa50d10af
< 1.10.5
MEDIUM 6.1 The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outp… wordfence
0c18e637-a117-4154-84b8-8afa84ac6feb MEDIUM 6.1 The WP likes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.… wordfence
0c0e9a09-0362-4046-a409-41a88154c7ba MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in js/window.php in the sourceAFRICA plugin 0.1.3 for WordPress allows remote a… wordfence
0c0c698e-a5c2-473c-8dfb-31745b7d7c38
< 1.0.6
MEDIUM 6.1 The Predictive Search for WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting via the predictive sear… wordfence
0c0c1e62-1a1c-4a76-bd99-7ede232dc965
< 4.3.24
MEDIUM 6.1 The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests… wordfence
0c00f3c0-8374-4966-9496-dd62f183f75a
< 1.1.2
MEDIUM 6.1 The Call Now Button WordPress plugin before 1.1.2 does not escape a parameter before outputting it back in an attribute … wordfence
0bf6d6f7-e63c-4ee6-a918-1da9940ac915 MEDIUM 6.1 The Smart DoFollow plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
0bf67b6d-5e72-433d-9e41-9fdf8d99a3ae
< 0.5.0
MEDIUM 6.1 The broken-link-manager plugin 0.4.5 for WordPress has XSS via the page parameter in a delURL action. wordfence
0bf1fe22-2cee-4828-bd68-7269b66152b3
< 10.1.76
MEDIUM 6.1 The WP Cost Estimation & Payment Forms Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in a… wordfence
0be5795a-9eea-40fc-9783-dbf501a2144d MEDIUM 6.1 The LH OGP Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
0bc784d4-4ecc-4f28-8e35-9e96e10a751c
< 1.6.3
MEDIUM 6.1 The SKU Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
0bc1f99e-1aa8-431a-a2ab-bdee5ece602f
< 1.2.7
MEDIUM 6.1 The 5 Anker Connect plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
← Prev 1003 1004 1005 1006 1007 1008 1009 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top