🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1015 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
02990dd6-707a-4154-8f01-f4e27a9deb05
< 1.6.8
MEDIUM 6.1 The Doctreat theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.6.7… wordfence
028b11f9-bca6-49bd-b2ac-e387d3a3bcb4 MEDIUM 6.1 The Go Animate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
026a2e0d-4d30-4133-9118-055026aa9f4a MEDIUM 6.1 The List Site Contributors plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'alpha' paramete… wordfence
026443b6-4ab5-4f31-8a8d-2019097bde4c MEDIUM 6.1 The Attorney theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3 due… wordfence
025a13e6-5f0a-49ca-bd63-44e4095072bd
< 1.5.2
MEDIUM 6.1 The Rate Star Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
02485b2c-a53c-4e9c-96ad-db1d95a1df0e
< 1.6.8
MEDIUM 6.1 The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
02399fc5-fe74-4ee5-ac63-78d971d2f99e
< 5.3.9
MEDIUM 6.1 The XStore Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5… wordfence
0234419b-9e39-4153-a3b7-bb913f2b6bcd
< 5.2.0.4
MEDIUM 6.1 The WP phpMyAdmin plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including … wordfence
02325b2a-af00-4b99-91ae-64163a8980fc MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in yousaytoo.php in YouSayToo auto-publishing plugin 1.0 for WordPress allows r… wordfence
022e4506-fe49-469d-ae48-641f121fc53b
< 2.3.3
MEDIUM 6.1 Reflected Cross-Site Scripting (XSS) vulnerability in Adam Skaat's Countdown & Clock plugin on WordPress via &ycd_type v… wordfence
0229b20f-65d7-4f55-a773-fd8da479723c
< 1.0.5
MEDIUM 6.1 wordfence
021916e5-c0f3-4232-b4f5-daee85d2136a
< 5.1.1
MEDIUM 6.1 The Document Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
020bed37-9544-49b7-941d-3b7f509fdfdf
< 5.1.5
MEDIUM 6.1 The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5… wordfence
0200e405-b3cc-4560-ab5d-4c0cf9f03366 MEDIUM 6.1 The NoFollow Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
01f798e7-f4e1-4cd8-b284-68101582fc2d
< 5.6.5
MEDIUM 6.1 The XStore Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5… wordfence
01e55868-9032-4f3d-830c-01dac94bb364 MEDIUM 6.1 The BuddyApp theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.2… wordfence
01d99cad-fb49-4260-9354-1cb1d532447d MEDIUM 6.1 The NextMove Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
01d5f559-d784-4399-9009-6edc584f8f09
< 4.9.9.2
MEDIUM 6.1 The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4… wordfence
01d5e5b5-033c-4690-9857-3339e2831340
< 2.1.2
MEDIUM 6.1 The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and Java… wordfence
01d19333-d315-4715-8365-719260ae0ee4
< 2.9.1
MEDIUM 6.1 The Email Subscribers & Newsletters plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 2.9.1 … wordfence
01d0016c-f693-426a-94cb-5611760fd2d0
< 1.0.23
MEDIUM 6.1 The Kormosala theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filter-title’ parameter i… wordfence
01cd3631-93fb-4016-baa4-8ea11b21acec
< 1.4.6
MEDIUM 6.1 The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_by' parameter i… wordfence
01cce0b2-b43c-4b79-89a0-c1842cab1edc
< 1.6.2
MEDIUM 6.1 The Max Addons Pro for Bricks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… wordfence
01cb63ab-2198-443a-8eee-ee4f1cf2fdc4
< 3.0.9
MEDIUM 6.1 The Testimonials plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
01c9f196-bcf1-401b-992a-e7a60f9447f7
< 3.4
MEDIUM 6.1 Cross-site scripting vulnerability in Simple Custom CSS and JS prior to version 3.4 allows remote attackers to inject ar… wordfence
← Prev 1012 1013 1014 1015 1016 1017 1018 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top