🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1017 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
00d8ef65-477a-49d0-92c1-b5d70b068c39
< 1.4.1
MEDIUM 6.1 The GLS Shipping for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
00c7b97b-4c5e-436a-967e-007ee1d283fb MEDIUM 6.1 The Contact Form 7 reCAPTCHA plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQU… wordfence
00c022a9-2062-4e99-8911-8cfad929a783
< 6.0.5
MEDIUM 6.1 The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter. wordfence
00ba947e-a9c8-4787-9acb-0fa6e0487347
< 4.1.14
MEDIUM 6.1 The Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 4.1.14 due to insuff… wordfence
00a9b83e-793e-46df-a3de-5728cf424d28 MEDIUM 6.1 The Widgetize Pages Light plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
00a96f3c-a6c9-4305-82ec-fa35570ac2af MEDIUM 6.1 The Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps plugin for WordPress is vulnerable to Reflected… wordfence
009084cf-0a49-41ab-8b3b-fe46c00a889b
< 1.6
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the Titan Framework plugin before 1.6 for WordPress allow remote … wordfence
008563a2-75c2-49f8-b581-a04b72ec2a10 MEDIUM 6.1 The WooCommerce TBC Credit Card Payment Gateway (Free) plugin for WordPress is vulnerable to Reflected Cross-Site Script… wordfence
00789ec1-8c0d-4c60-a4b6-29acace4c865 MEDIUM 6.1 The Claue - Clean, Minimal Elementor WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting in … wordfence
00717a4e-0157-4dbd-81b4-d88b476b1964 MEDIUM 6.1 The LH Email plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.12… wordfence
006945a3-5f54-4bb8-9522-c832d59624a0
< 4.1.2
MEDIUM 6.1 The Comfino Payment Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_q… wordfence
00622a39-7230-4263-8e25-b0917df80191 MEDIUM 6.1 The Edit Comments XT WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_S… wordfence
0054c17a-09f1-4b54-afa4-6743cbb6ff51 MEDIUM 6.1 The ListingPro Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
0051e869-47b1-42ea-911a-49a4462d33ca MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in forms/messages.php in the WP-Contact (wp-contact-sidebar-widget) … wordfence
0042d5ba-62de-404e-9516-67cae618f684
< 0.98
MEDIUM 6.1 The Fastly plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 0.… wordfence
004206fd-c46e-48d7-93f1-884b3261fdb6
< 1.6.7
MEDIUM 6.1 The AccessPress Social Icons plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including… wordfence
0037c6ba-7b77-4529-8c23-002624332f9b
< 3.8.1
MEDIUM 6.1 The Support Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
003522cc-b425-4210-9740-5c1b0cce076d MEDIUM 6.1 The My Quota plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … wordfence
0034df15-6039-422b-980c-009c2491a752 MEDIUM 6.1 The Listeo-Core - Directory Plugin by Purethemes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
002f5f49-d744-41a4-97b0-e22ad2d6b45b MEDIUM 6.1 The Blog Designer PRO for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up … wordfence
00272fe2-52aa-4183-8b57-6b51ad57c657
< 1.24.4
MEDIUM 6.1 The Forminator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
001e066f-6add-4426-8cd7-32229a9188d1
< 1.4.7
MEDIUM 6.1 The User Activity Log plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘txtsearch’ param… wordfence
00149f27-8301-410e-898a-9363a83fdeae MEDIUM 6.1 The WooCommerce Estimate and Quote plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up t… wordfence
001289a3-a1a9-441f-b399-e9b699094e1a
< 5.8002
MEDIUM 6.1 The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wit… wordfence
a53430c1-7a2d-4c05-94ee-691e06759797
< 2.2
MEDIUM 6.0 The Export Users Data CSV plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.1. Thi… wordfence
← Prev 1014 1015 1016 1017 1018 1019 1020 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top