🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1007 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0bc1ebf6-2797-43cc-8c7a-930da29d6c78
< 2.1.7
MEDIUM 6.1 The Popup Anything – A Marketing Popup and Lead Generation Conversions plugin for WordPress is vulnerable to Reflected… wordfence
0bbeab52-59a9-4d8d-8e3e-ebcbbca9816b MEDIUM 6.1 The CoSign Single Signon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SEL… wordfence
0bb13936-cbc0-4cba-bd62-ef6d9728a65a MEDIUM 6.1 The AJAX Random Post plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the interval and count pa… wordfence
0ba9568f-8ecc-4395-a5a4-bdbb280d3c37 MEDIUM 6.1 The RS Survey plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
0b8a9c85-a7cd-469c-834b-d1d89387cf63
< 2.5
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Pods plugin before 2.5 for WordPress allows remote attackers to inject a… wordfence
0b7073e8-10cf-4fe0-9eb6-f9acd509598c
< 1.8.3
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the geo search widget in the Geo Mashup plugin before 1.8.3 for WordPress al… wordfence
0b51caf3-eff4-491f-b354-7d8939548a64 MEDIUM 6.1 The File Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post_id’ parameter i… wordfence
0b4ec57a-c52a-40c1-897a-db67efbd7177
< 3.7.24
MEDIUM 6.1 wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might… wordfence
0b4651d8-dad7-4f6f-a47d-2095b9d2bdca
< 1.0.16
MEDIUM 6.1 The Continuous Image Carousel With Lightbox for WordPress is vulnerable to Reflected Cross-Site Scripting via the search… wordfence
0b1718bd-dce8-4c18-ac3f-a2974af0a671 MEDIUM 6.1 The Wolverine Framework plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
0b151b74-b08c-4d84-aca8-5fb768c84a9e
< 4.0
MEDIUM 6.1 The VR-Frases (collect & share quotes) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versi… wordfence
0b04ea62-8e6b-4876-a9f8-7bc342e837f4
< 5.4.4
MEDIUM 6.1 The Jannah WordPress theme before 5.4.4 did not properly sanitize the options JSON parameter in its tie_get_user_weather… wordfence
0afc702c-4d46-489d-abf1-047b44fbe2fc MEDIUM 6.1 The Hide Login+ plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
0aeaeb51-23ae-46f3-ba81-be261fc1aa29 MEDIUM 6.1 The Time Based Greeting plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
0ad806df-0a5c-4ef0-a335-2e34c9b62662
< 1.2.3.7
MEDIUM 6.1 The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_s… wordfence
0ad0eed1-777a-432b-a190-b8a7ed10d71a
< 1.6.5
MEDIUM 6.1 The Gmedia Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
0ac5ab31-83d9-42be-a6b1-f65303e9c801 MEDIUM 6.1 The Domain Sharding plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
0ab82117-73dd-4257-8dfc-01dadcc3a83f MEDIUM 6.1 The WP-JS plugin for WordPress contains a script called wp-js.php with the function wp_js_admin, that accepts unvalidate… wordfence
0ab4cdcd-1ca8-4ee9-87ab-bf4ce33f94d3 MEDIUM 6.1 The Pricing Tables for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter … wordfence
0aad7f55-d1f0-45f9-ba8b-74170c32374f
< 3.0.6
MEDIUM 6.1 The EventPrime plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.… wordfence
0aa3bee5-a194-4618-8f32-a0a781fe8dc6
< 4.0.4
MEDIUM 6.1 The spotim-comments plugin before 4.0.4 for WordPress has multiple XSS issues. wordfence
0a9dd9b6-28c7-4f7d-95bb-e93ccc6abc30 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in uploader.php in the WP Silverlight Media Player (wp-media-player) plugin 0.8… wordfence
0a99ccde-4c8c-4c77-9199-c21dba35c19f
< 3.0.8
MEDIUM 6.1 The Mega Menu plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘_wpnonce’ parameter in v… wordfence
0a95f73a-eaf7-4b8c-b127-0ceef87c80fb
< 1.3.2
MEDIUM 6.1 The CF7 Invisible reCAPTCHA plugin before 1.3.2 for WordPress has XSS. wordfence
0a934aad-5097-4fec-871b-4eb601240db2 MEDIUM 6.1 The Grand Photography WordPress theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
← Prev 1004 1005 1006 1007 1008 1009 1010 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top