πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1096 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1b038c9e-9053-43aa-99f2-cba660d2a7ff MEDIUM 5.4 The Min and Max Purchase for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versio… wordfence
1accc41e-41d2-49e3-a80a-6b95b02cb42e
< 6.10.3
MEDIUM 5.4 The Site Reviews plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… wordfence
1a5d9290-b480-45f7-9ac7-a20475b805e8
< 2.0.4
MEDIUM 5.4 Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Refle… wordfence
1a0fcd50-e9d6-49a5-979f-61f953b1a1cd
< 1.9.6
MEDIUM 5.4 The Safe SVG plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.5 due to i… wordfence
19e9a9f7-d2e3-4ebb-b121-99c7c81ede4f
< 4.16.3
MEDIUM 5.4 The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allow… wordfence
19d724f3-96fb-4834-aa56-6b8d30f0e34d
< 1.8.4
MEDIUM 5.4 The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when g… wordfence
19c88a9a-1f97-4a46-b759-9ca030d577e7
< 3.7.40
MEDIUM 5.4 WordPress Core is vulnerable to open redirect in versions up to 6.0.3. This is due to insufficient validation of the 'Re… wordfence
1998cadb-2eb3-4819-aa7c-59e4f777c7f8
< 2024.5
MEDIUM 5.4 The Stop Spammers Security | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request … wordfence
191d5bcc-70d8-430b-9215-00ffdc04be87
< 2.7.1
MEDIUM 5.4 The JSM file_get_contents() Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up t… wordfence
18e2e0e5-495f-4f55-b7d8-94193fc2ad12
< 1.13.3
MEDIUM 5.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets … wordfence
18dd1b86-3206-4cd7-a20b-33240c139aa5
< 3.1.5
MEDIUM 5.4 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data and loss of dat… wordfence
18b64b4a-e290-4efb-baa6-5cceb988ac87 MEDIUM 5.4 The The Job Board Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and… wordfence
18b2d99a-f55c-4a05-8442-e1fddd59181f
< 4.10.25
MEDIUM 5.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the plu… wordfence
18acd104-a5a5-4811-9aea-abc227a1712c MEDIUM 5.4 The Basic Log Viewer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
18a41bef-feed-4096-a1f4-9c99caac6ce9
< 1.1.5
MEDIUM 5.4 The Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4… wordfence
17f8e2a0-b23f-4706-8438-7a6573a29933
< 1.0.95.1
MEDIUM 5.4 The Rank Math SEO plugin for WordPress is vulnerable to Server Side Request Forgery in versions up to, and including 1.0… wordfence
17f2a0d5-6640-4ef9-a219-93a92571a5d3
< 1.1.12
MEDIUM 5.4 Pinboard 1.1.10 theme for Wordpress has XSS. wordfence
179eb680-e8d8-4918-96e3-e67217771c29
< 1.9.5.1
MEDIUM 5.4 The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress i… wordfence
179c4920-5a03-4cf4-9e77-a814c3004769
< 2.04
MEDIUM 5.4 The display-widgets plugin before 2.04 for WordPress has XSS via the wp-admin/admin-ajax.php?action=dw_show_widget id_ba… wordfence
16f40b76-8f69-46de-a3e0-b7124dc74c00
< 6.3.2
MEDIUM 5.4 The Advanced Custom Fields Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
16800ece-da9c-431b-a015-42bd30b646e2
< 1.8.2
MEDIUM 5.4 The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This… wordfence
1671e437-09f0-46bc-87ef-3a5712c3dc98
< 1.3.13
MEDIUM 5.4 The Dynamics 365 Integration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… wordfence
1665f2d0-899b-4f9b-91b1-e5799c3b4d3d
< 5.4.22
MEDIUM 5.4 The Woffice Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
160740a2-f5e1-49d6-a380-e6bf33646300 MEDIUM 5.4 The examapp plugin 1.0 for WordPress has XSS via exam input text fields. wordfence
15c8addc-e40b-4ad2-9e7b-c721d10164d6 MEDIUM 5.4 The GS Insever Portfolio plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
← Prev 1093 1094 1095 1096 1097 1098 1099 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top