🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1014 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
04402ff7-14d3-4454-bfc3-1db30c93f716
< 1.0.3
MEDIUM 6.1 The Epic Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
043ed446-3af3-4d90-8da7-b1fe73e06bba MEDIUM 6.1 The NextGen GalleryView plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
0435ae14-c1fd-4611-acbe-5f3bafd4bb6a
< 1.15.1
MEDIUM 6.1 The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s para… wordfence
041e635a-9f97-4f54-8ecb-57bbbc321cfc
< 4.11.0
MEDIUM 6.1 The ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the error parameter in versio… wordfence
041807ab-9354-4438-8e8a-77140f41eedb
< 1.3.3
MEDIUM 6.1 The ultimate-form-builder-lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ufbl_form… wordfence
03ddef11-04cb-4639-afb0-f123b339b9ae
< 2.2.6.2
MEDIUM 6.1 The All in One SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
03c5f9c6-3346-43fc-beb3-d0269b5599d1 MEDIUM 6.1 The magayo Lottery Results plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
03c0e3c8-9566-48ea-909f-08cdff422473 MEDIUM 6.1 The S3Player – WooCommerce & Elementor Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
03afffcc-02fe-4054-8876-6a4e4d9de071 MEDIUM 6.1 The SIP Calculator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
03733eb8-63c7-4798-9d87-e80a6112da6e MEDIUM 6.1 The Daily Inspiration Generator plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 2.… wordfence
0372efe4-b5be-4601-be43-5c12332ea1a5
< 5.1.2
MEDIUM 6.1 The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. Th… wordfence
03509ba4-1e92-425d-9d2a-4e5bd96b6340 MEDIUM 6.1 The Travel & Tours Meta Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
03444a33-f1ad-439f-ae19-4013859959f0 MEDIUM 6.1 The Restrict Taxonomies plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
033b0f16-02fb-44b9-9e07-2393afe14cc5 MEDIUM 6.1 The User Rights Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
0324852f-9e19-467c-9b0b-4c9fe2dd1cc0
< 2.2.3
MEDIUM 6.1 The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2… wordfence
03226722-000c-4bfe-a09b-e75882274845 MEDIUM 6.1 The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
030def71-2949-46d5-a545-f3472433324e
< 3.1.4
MEDIUM 6.1 The WP Google Fonts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ googlefont_ajax_nam… wordfence
030d4038-cf31-4ad9-a89a-6cf5f6177c2e MEDIUM 6.1 The StyleBidet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all versions up … wordfence
02f8faff-8629-490b-9bc7-378ebffcfd0f
< 4.4.6
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP… wordfence
02ecd818-4c96-463e-b9ab-5900c1d01a39 MEDIUM 6.1 The Photoxhibit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'gid' parameter in the ‘e… wordfence
02eadae8-7aa6-42f5-b807-9ed82332fa72
< 3.1.1
MEDIUM 6.1 The Essential Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
02ea41ea-870e-4f32-bfad-d7e8248ff3b1
< 2.3
MEDIUM 6.1 The Export Media URLs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
02bfc849-0f36-4647-9290-eddbacdb419b MEDIUM 6.1 The Updraft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘backup_timestamp’ paramete… wordfence
02bf7820-3314-4c12-aecd-074869e1c602
< 3.1
MEDIUM 6.1 The CSS3 Accordions for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
02b9a40a-2fb6-4d75-b4b4-a83b95df90e1
< 1.7
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Easy Contact Form Solution plugin before 1.7 for WordPress allows remote… wordfence
← Prev 1011 1012 1013 1014 1015 1016 1017 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top