πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1085 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5b49f379-7ae1-4da9-8e1b-cbe5a561b803
< 1.2.11
MEDIUM 5.4 Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote… wordfence
5b2813d6-6ef5-4629-b079-bec3ad25d661 MEDIUM 5.4 The WP-ISPConfig 3 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
5b1a2126-978c-48fa-b260-abfd26d0ec97
< 1.5.23
MEDIUM 5.4 The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS. wordfence
5aa41416-c945-489b-81a3-1222a5e24469
< 4.0.4
MEDIUM 5.4 Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers … wordfence
5a9e62de-3e70-424f-b8e5-2a5f07ca182d
< 2.3.17
MEDIUM 5.4 The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sev… wordfence
5a3a5dd8-1608-4a73-a571-25da811e4605
< 2.1.0
MEDIUM 5.4 Cross-Site Request Forgery (CSRF) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers to t… wordfence
5a30e5dc-1f15-40ce-9703-1e1add1df6da
< 2.2.15
MEDIUM 5.4 The The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to a… wordfence
5a2eb266-a050-48b9-a0bb-5d48b2c0f970 MEDIUM 5.4 Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM V1.8.7 is affected by: Cross Site Scripting via the Business Name … wordfence
59fdfdf3-e9fe-44d2-82f4-7a612a51d376 MEDIUM 5.4 The Application Passwords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reject_url' para… wordfence
59931266-766f-42d2-bcde-04d694a444b0
< 2.5.1
MEDIUM 5.4 The Smart WooCommerce Search plugin for WordPress is vulnerable to unauthorized modification and loss of data due to mis… wordfence
597660c5-8c99-40b1-8780-5a2ab9c07656 MEDIUM 5.4 The Pexels: Free Stock Photos plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a… wordfence
59532447-1d74-4d34-85f5-d89b65a001d8
< 1.4.1
MEDIUM 5.4 The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to unauthorized back-up location chang… wordfence
592867de-17b5-4461-a479-ecfbbef55a0b
< 4.0.5
MEDIUM 5.4 Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote… wordfence
58da5adc-bb2e-409d-a623-12b19e6da138
< 1.8.1
MEDIUM 5.4 The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authe… wordfence
58b7736a-e3e0-4ecd-9adf-284568b02ef7
< 2.3.6.19
MEDIUM 5.4 The Swift Performance Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
58b59e65-420c-45f5-a34c-2d2003f4e3ae
< 1.11.9
MEDIUM 5.4 A reflected XSS vulnerability was found in includes/admin/table-printer.php in the Broken Link Checker plugin 1.11.8 for… wordfence
58209530-9e68-4d2c-a723-e6a164db7f46
< 1.4.18
MEDIUM 5.4 The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
57d90ba7-b655-4655-981c-548ff96c3bb7
< 5.0.8
MEDIUM 5.4 The WP Latest Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inclu… wordfence
5776ae23-3846-41bf-92dd-948230c334bf
< 4.19.3
MEDIUM 5.4 The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the Syste… wordfence
575b11a3-9fa4-4ee0-8f19-7d53e6c1785f
< 9.0.11.007
MEDIUM 5.4 The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including,… wordfence
570942bf-49b1-4217-abc6-5e83f27d9824
< 1.0.7
MEDIUM 5.4 The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its set… wordfence
5708a414-7cd8-4926-8871-3248ebf4c39d MEDIUM 5.4 The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to unauthor… wordfence
559c83e9-8c85-4d2a-b835-d6b314ba7eab
< 2.3.2
MEDIUM 5.4 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to authorization bypass due to a missing c… wordfence
55827029-479e-4c4c-ba33-203075e1bbbc
< 4.9.8
MEDIUM 5.4 The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to missi… wordfence
55234307-9d51-4fe8-bc22-78d32a5fed11
< 3.0.1
MEDIUM 5.4 The Solid Central – Site Management, Backups, Security, and Reporting plugin for WordPress is vulnerable to Stored Cro… wordfence
← Prev 1082 1083 1084 1085 1086 1087 1088 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top