🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1016 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
01c3c913-2296-4ec3-b7cb-6418ab2f0ea1
< 3.1.28
MEDIUM 6.1 The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in… wordfence
01b9f536-cdab-4e38-b935-008cbd899a98 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in tinymce/popup.php in the Ruven Toolkit plugin 1.1 and earlier for WordPress … wordfence
01b55b59-3107-4711-8be2-8b0803c0fa69
< 0.7.2
MEDIUM 6.1 The share-on-diaspora plugin before 0.7.2 for WordPress has reflected XSS in share URL parameters. wordfence
01b384dd-112b-4680-9a37-05e19f4fca5e
< 3.3.4
MEDIUM 6.1 The WP2LEADS | WordPress und KlickTipp einfach verbinden – WooCommerce und KlickTipp einfach verbinden plugin for Wor… wordfence
01a120f0-fbdb-4836-a341-31452cc7ed0c MEDIUM 6.1 The Send email only on Reply to My Comment plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… wordfence
01878991-37c7-4c7b-b68c-d59ca66521e7 MEDIUM 6.1 The The Awesome Feed – Custom Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown… wordfence
01857d1d-4b6c-4ab0-b2ef-6a948daedbe0
< 2.4.7
MEDIUM 6.1 The myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty plugin for WordPress is vulnerable to Cross-Site S… wordfence
0182ca6c-23f8-4212-bfd8-cb898e98b37b MEDIUM 6.1 The Category Post List Widget plugin for WordPress is vulnerable to stored Cross-Site Scripting via the ‘custom_css’… wordfence
01724317-c2a1-45fc-b7da-7896eee5cd4a MEDIUM 6.1 The Simple Post Meta Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
016c56c0-38d2-4f84-a0bc-3c6c25847603
< 250214
MEDIUM 6.1 The s2Member Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
0158ebd2-1f32-4269-aa1e-e258dafa80ff MEDIUM 6.1 The MaxA/B plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.2.… wordfence
014dd0ee-0bd0-477c-a0fa-bde8ce5a099c
< 1.0.1
MEDIUM 6.1 The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all vers… wordfence
014da588-9494-493e-8659-590b8e8c14a6
< 3.6.0
MEDIUM 6.1 The Spreadsheet Integration and Spreadsheet Integration Professional plugins for WordPress are vulnerable to Reflected C… wordfence
014803c8-3319-48ad-98c7-d1f372d37ff2
< 1.3.2
MEDIUM 6.1 The Contact Form 7 Database Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tmpD’ p… wordfence
0136b4e4-e22b-43a3-bad5-6fe397cdd7c8 MEDIUM 6.1 The ViperBar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0 … wordfence
01367ff4-1108-4ea5-90d1-030e384f1734 MEDIUM 6.1 The Om Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'om_stripe_message' parameter… wordfence
01179ac2-ad68-4a5d-af67-70d57ed611d2
< 2.1.4
MEDIUM 6.1 The Easy Digital Downloads (EDD) Simple Shipping extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x bef… wordfence
010ce1c3-dd07-4ed6-8908-0909c0842be8
< 1.2.33
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for… wordfence
0104fa43-06c6-4e98-bced-4dd6ce355203 MEDIUM 6.1 The Emu2 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.83b du… wordfence
0104d718-2b55-4d2e-93db-dcca7da2913d MEDIUM 6.1 The Lijit Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
00fe4d88-0481-4861-ad26-a2493ffacdc6 MEDIUM 6.1 The my flatonica and my wooden under construction themes for WordPress are vulnerable to Reflected Cross-Site Scripting … wordfence
00fbbd00-c98e-41b3-9777-3a0d1295c24b
< 2.2
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protect… wordfence
00fa2ca1-a1bd-4b58-ae64-1b61534c1e3d
< 1.1.4
MEDIUM 6.1 An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scriptin… wordfence
00e71f8e-1657-4713-af99-8b8766080c3f MEDIUM 6.1 The Mojo Under Construction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
00d94fbc-3057-45f0-8b68-aa08f97ca372 MEDIUM 6.1 The EELV Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
← Prev 1013 1014 1015 1016 1017 1018 1019 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top