πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1091 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3b798c64-3434-427d-b578-5abbdac8cd0e MEDIUM 5.4 The 0mk Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2… wordfence
3b7108fc-0eb2-4f9f-b747-3b83c57a1b53
< 0.14.11
MEDIUM 5.4 The webp-express plugin before 0.14.8 for WordPress has stored XSS. wordfence
3b378256-2d9b-4aad-abfe-fecfc76f0bb4 MEDIUM 5.4 The SVG Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions… wordfence
3ad60a11-e307-4ec9-9099-091a87ff1d3b
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… wordfence
3abe2de8-9127-4ef0-9194-cf331b20868a
< 2.3.14
MEDIUM 5.4 The Responsive Gallery Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
3a71b8da-73dd-488e-b553-77116731f13f
< 3.7.11
MEDIUM 5.4 The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 all… wordfence
39e501d8-88a0-4625-aeb0-aa33fc89a8d4
< 4.6.0
MEDIUM 5.4 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
39bbe18a-0212-4bfe-861f-2a213d67baec
< 1.2.11
MEDIUM 5.4 The Fast Flow WordPress plugin before 1.2.11 does not sanitise and escape the page parameter before outputting back in a… wordfence
389277fd-e47e-42df-9305-61ceedbcfb29
< 4.2.3.1
MEDIUM 5.4 The LearnPress plugin for WordPress is vulnerable to unauthorized access of user data due to a missing capability check… wordfence
387d28fa-f582-4d68-a781-fc210ef5bd30
< 3.1.7
MEDIUM 5.4 The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
385c6324-3d8e-4dc7-b8ca-309b05e7bdcc
< 1.6.0
MEDIUM 5.4 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
36d37997-ac50-4d00-bc12-f3904483e15f
< 5.7.8
MEDIUM 5.4 The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by autho… wordfence
360010f3-9053-4c69-a4e8-12f0c77ba746
< 7.5.45.7212
MEDIUM 5.4 The FV Flowplayer Video Player plugin for WordPress is vulnerable to unauthorized redirects in all versions up to, and i… wordfence
35fb658f-6ffa-4df7-bfcd-25307d89fc26
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… wordfence
34fb64d5-e152-4950-9ef4-6d53a97a56fb
< 3.3.2
MEDIUM 5.4 The Categories Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
34d396b2-f19f-47b3-bf9e-f2f14dd0b9be MEDIUM 5.4 The URL Shortener plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an unk… wordfence
34c98bb0-2e28-4ed4-8848-04edb66eef96 MEDIUM 5.4 The Debug Meta Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
346a5b00-fb76-4413-a935-a2df4dc51984
< 6.15.13.1
MEDIUM 5.4 The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on t… wordfence
345f3354-d2cb-4b92-a25d-9551a5992919
< 4.17.0
MEDIUM 5.4 The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Profi… wordfence
34021007-b5d3-479b-a0d4-50e301f22c9c
< 2.09
MEDIUM 5.4 The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to unauthorized access of data due to a mis… wordfence
33d70481-4652-44f4-99cf-67cc1ffab66a
< 5.1.11
MEDIUM 5.4 The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bu… wordfence
33585791-be40-438c-bebc-8852e7cf8ae5
< 6.4.6.2
MEDIUM 5.4 The Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App plugin for W… wordfence
334ff8d7-1313-4c19-aed3-0c4625b895ab
< 1.0.354
MEDIUM 5.4 The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present… wordfence
332c0829-316d-4037-8c50-02d6c92cdb10
< 7.3.7
MEDIUM 5.4 The Quiz And Survey Master plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and… wordfence
32ca6e56-add9-4024-831f-5dfa5130a7d8
< 2.4.7
MEDIUM 5.4 The Easy Custom Auto Excerpt plugin 2.4.6 for WordPress has XSS via the tonjoo_ecae_options[custom_css] parameter to the… wordfence
← Prev 1088 1089 1090 1091 1092 1093 1094 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top