πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1261 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d3ace116-69e1-44b1-a63f-693153ab4679
< 1.3.6
MEDIUM 4.8 The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size… wordfence
cfc59270-d08c-4b78-9863-4bb88120b878
< 1.0.19
MEDIUM 4.8 The Petfinder Listings WordPress plugin through 1.0.18 does not escape its settings, allowing high privilege users such … wordfence
cf44a96e-0efb-4363-9f49-ba4a82924569
< 1.9.6
MEDIUM 4.8 The Video Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions … wordfence
cede7e6f-e3e8-479b-9c7b-91c390ed3936
< 2.0.69
MEDIUM 4.8 The Export customers list csv plugin for WooCommerce is vulnerable to CSV Injection in versions up to, and including, 2.… wordfence
cde35356-daba-47ff-9278-21447337f0c7
< 1.0.11
MEDIUM 4.8 The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege use… wordfence
cdb3cdf8-7563-4ccd-83fe-7ebd13fa7936
< 1.7.7
MEDIUM 4.8 The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the p… wordfence
cbd4f08c-9989-4af9-b615-1db82909a1db
< 3.6.3
MEDIUM 4.8 The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier… wordfence
cb714378-ed60-4bf1-8c9c-b37515ddb353
< 3.5.9
MEDIUM 4.8 The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing hi… wordfence
c95210ba-65f6-4bf8-8986-f537f1854d02
< 2.7.8
MEDIUM 4.8 The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded v… wordfence
c6e7ada1-c5ff-4a05-92e1-d681fc659956 MEDIUM 4.8 The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing maliciou… wordfence
c32824cc-8895-462f-bd5b-03b8da4db680
< 1.9.7
MEDIUM 4.8 The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][page] parameter to wp-admin/options.p… wordfence
c1a0d446-63b6-4265-a542-345d766faf15
< 1.8.1
MEDIUM 4.8 The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which co… wordfence
c0dfa035-78fe-426f-a018-7bb2f22f0dd7
< 4.03
MEDIUM 4.8 The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege u… wordfence
c09536b3-9f8d-4b11-b69a-684b65078870
< 1.9.7
MEDIUM 4.8 The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[browser_redirect][redirect_by_language] paramete… wordfence
bede3241-6383-4bdb-ac28-cd9781b608d1
< 1.68.7
MEDIUM 4.8 Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plug… wordfence
bdc46d3e-dfb7-4586-86d2-8e4b3805ec22
< 10.0.4
MEDIUM 4.8 The WP Editor.md plugin before 10.0.4 for WordPress allows XSS via the comment area. wordfence
bdb5ae36-6ce2-4c26-8047-6bbbdce530c6
< 2.0.3
MEDIUM 4.8 WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline… wordfence
bd650510-2d1c-48a1-a5fa-d4c26f3d030c
< 1.8.176
MEDIUM 4.8 The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow … wordfence
ba677822-a588-484e-a0aa-a9eda2954d01
< 2.5.1.9
MEDIUM 4.8 These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact… wordfence
b8a598cf-bdd6-4249-a367-e3e8c6e3ef15 MEDIUM 4.8 A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote at… wordfence
b67710d7-976b-4a65-bad3-091a97aceb00
< 2.7.5
MEDIUM 4.8 The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is … wordfence
b6616c4b-6021-42c8-afe1-bfd789b895ca
< 1.7.0
MEDIUM 4.8 The WP Sitemap Page WordPress plugin before 1.7.0 does not properly sanitise and escape some of its settings, which coul… wordfence
b5018aac-59fb-4d95-bbdd-8ceaa4f8fad1
< 1.8.3
MEDIUM 4.8 The WP YouTube Live WordPress plugin before 1.8.3 does not validate, sanitise and escape various of its settings, which … wordfence
b3c65619-e96c-47e1-b42a-a85d0b5237d9
< 1.7.0
MEDIUM 4.8 The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter. wordfence
b13f6a3f-cab6-4aff-a96e-58250fcf655a
< 3.7.35
MEDIUM 4.8 is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is alre… wordfence
← Prev 1258 1259 1260 1261 1262 1263 1264 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top