πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1008 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0a8a49c4-21e8-447c-94da-8241c7d66c29 MEDIUM 6.1 The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to a… wordfence
0a8972da-ac16-4010-a639-91e3ee46b36e MEDIUM 6.1 The 360 Product Rotation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
0a769f8a-c1c1-4be1-b7ae-e1cb6eeda28c
< 2.3.2
MEDIUM 6.1 The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before ou… wordfence
0a6e56ac-76e6-4ba0-8fbb-159fd8cb7dd1 MEDIUM 6.1 The Rezdy Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin… wordfence
0a66f763-dc1a-4b8e-9193-88d790cc64ec
< 1.1.3
MEDIUM 6.1 The WP Gravity Forms Zendesk plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1… wordfence
0a617faf-cc1f-453b-b5aa-e357613adee4
< 1.2.5
MEDIUM 6.1 The Connector for Gravity Forms and Google Sheets plugin for WordPress is vulnerable to Open Redirect in all versions up… wordfence
0a60ed96-a2c9-45a5-a294-a48c0155683e
< 2.2.0
MEDIUM 6.1 The Leadfox for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
0a5c8f46-a686-4b77-8a22-8dec92a96350
< 250214
MEDIUM 6.1 The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plug… wordfence
0a5ac584-61e4-4318-9e8d-9b5a7f1daf3d MEDIUM 6.1 The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not san… wordfence
0a5a4b0e-f490-4f62-83cc-bef892e4c6ec MEDIUM 6.1 The Autocompleter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
0a55956f-3bda-46ac-9d6e-24dada30046f MEDIUM 6.1 The Tidekey plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1 d… wordfence
0a45d62f-bd41-4a69-be61-c4d6a7ec555c MEDIUM 6.1 The FlagEm plugin for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and output … wordfence
0a439cd6-c9d1-42d0-9067-4b425f2869a9
< 1.5.9
MEDIUM 6.1 The Portfolio Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the GET 'id' parameter in… wordfence
0a3cfa87-ad48-401c-b823-f61d5a7af680
< 1.2.3
MEDIUM 6.1 The wp-rollback plugin before 1.2.3 for WordPress has Cross-Site Scripting. wordfence
0a33282c-2adb-4f26-8fc4-918a48bfd040
< 1.2
MEDIUM 6.1 The prettyPhoto plugin for WordPress is vulnerable to DOM Cross-Site Scripting in versions up to, and including, 1.1 due… wordfence
0a2f60a9-c061-4ef9-a582-c82eb1311e5a
< 2.4.3
MEDIUM 6.1 The search functionality of the Greenmart theme 2.4.2 for WordPress is vulnerable to XSS. wordfence
0a2740bc-5d4a-4449-b28a-5bf84b03c878 MEDIUM 6.1 The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputti… wordfence
0a1824ff-7dc3-4b21-aaa2-0079c5c0b5b8
< 9.4.2
MEDIUM 6.1 The Doliconnect plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 9… wordfence
0a0314ab-4658-48c4-9a90-48a19cbceeaa MEDIUM 6.1 The RDP Linkedin Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
09f590ad-c99a-4577-a709-98c88d3acc87
< 2.0.3
MEDIUM 6.1 The Authors List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the al_id parameter in version… wordfence
09ee0155-7424-42ff-bfd6-244912857009
< 2.8.10
MEDIUM 6.1 The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress for WordPress is vulnerable to Reflected C… wordfence
09c4412f-69ea-4214-ae07-6b6b8ff1c101
< 3.04
MEDIUM 6.1 The Weather Atlas Widget plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including… wordfence
09c04863-a454-4f05-9403-aff39dbccd43
< 6.30.04
MEDIUM 6.1 The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
09b0bfd3-93a7-4f13-828d-772f54085a60
< 3.4.4
MEDIUM 6.1 The Interactive World Map plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter … wordfence
09afbbd2-52c6-48a6-a2f0-b1509d864e7e
< 2.3.22
MEDIUM 6.1 The Quran multilanguage Text & Audio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'soura… wordfence
← Prev 1005 1006 1007 1008 1009 1010 1011 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top