ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1043 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
56ce85d3-89f3-461a-8268-7d549e9c2baf MEDIUM 5.5 The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could all… wordfence
56953c6f-7ff9-45bf-9265-01240938e395
< 2.4.9
MEDIUM 5.5 The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting via the pay_price() function, in versions up … wordfence
567c4487-32e3-4afd-aec7-2f8171a49ebc
< 1.2.3.10
MEDIUM 5.5 The UsersWP plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.2.3.9 via the proces… wordfence
5617f917-ecb5-4c64-b421-e4af14c17eb7
< 1.3.9.9
MEDIUM 5.5 The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions … wordfence
55f7914f-9731-4b43-b2c0-b3474508e40a MEDIUM 5.5 The reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6 du… wordfence
553255fb-2bec-48e8-bb16-1e7f66674282
< 3.0.7
MEDIUM 5.5 The Spacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, a… wordfence
550fcbbd-254d-4b3c-a240-8afcf9f6937e
< 0.2.18
MEDIUM 5.5 The 4ECPS Web Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
546d4f19-0e6f-447b-95c9-d86291477c80 MEDIUM 5.5 The Database Browser plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters including … wordfence
53ddfd2d-7af1-4561-ab76-5cb3238e8f8b
< 2.21.0
MEDIUM 5.5 Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress… wordfence
52cd845d-9c63-4f96-8ce6-fdaa6f535447
< 2.3
MEDIUM 5.5 The Send From plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2 du… wordfence
52944aa6-a6ee-46ce-bd0c-18c69fe1ada7
< 1.3
MEDIUM 5.5 The WP Duplicate Page WordPress plugin before 1.3 does not sanitize and escape some of its settings, which could allow h… wordfence
5269ea0a-b0e9-433a-a166-28d23bfb6b4e
< 1.30
MEDIUM 5.5 wordfence
52574d99-1ffe-4152-bf13-9cdd11d7300a
< 3.6.5
MEDIUM 5.5 The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in v… wordfence
5223d6c3-9fe0-4ac5-bd69-990a13b17826 MEDIUM 5.5 The 3dady real-time web stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dady_input_te… wordfence
51e4f7ac-efc5-492c-b7a4-eea6d5f69e0d MEDIUM 5.5 The PlanSo Forms WordPress plugin through 2.6.4 does not escape the title of its Form before outputting it in attributes… wordfence
5193d1c0-5111-4e97-a433-a41a76acbde9
< 3.5.2
MEDIUM 5.5 The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting due to sanitization and escaping on an unspec… wordfence
514aa001-24c8-4624-8e25-f17b8454354c
< 1.5.9
MEDIUM 5.5 The Direct Checkout – Quick View – Buy Now For WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
51178e18-ae8b-4a7f-974d-23346a8dbc52
< 6.3.6
MEDIUM 5.5 The Advanced Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field groups in all ver… wordfence
50b811e0-c1f4-4970-a340-8c1619456e29
< 2.21.3
MEDIUM 5.5 The GiveWP WordPress plugin before 2.21.3 does not properly sanitise and escape the currency settings, which could allow… wordfence
50b0eb50-fe25-487f-b5bc-13659be58ae4
< 1.7
MEDIUM 5.5 The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users… wordfence
50518a54-16d8-4467-beca-a6b8196ed9b9
< 1.7.1007
MEDIUM 5.5 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio… wordfence
4f997c20-38f6-4968-b7de-8f28f825c7fd
< 3.8.4
MEDIUM 5.5 The Social Media Share Buttons plugin for WordPress is vulnerable to stored cross-site scripting in versions up to, and … wordfence
4f93fb48-3963-4a98-9c70-eef667b254df MEDIUM 5.5 The Auto More Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions u… wordfence
4f60a6aa-8420-4f7e-9863-5b69774201ef MEDIUM 5.5 The Confirm User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
4ef11b08-534b-47eb-989c-7cc1c8853fb8
< 1.1.4.5
MEDIUM 5.5 The BEAR plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.4.4 due… wordfence
← Prev 1040 1041 1042 1043 1044 1045 1046 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top