πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1267 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e55ba61d-6fd0-4269-8ee9-3b8645d52e1d
< 4.6.3
MEDIUM 4.7 The Poll Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 4.6.2… wordfence
e52c53c1-4f04-4075-9329-d93fabf5a6ce
< 2.0.9
MEDIUM 4.7 The WPCode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.8. Thi… wordfence
dede9cfc-61f1-4df1-bd40-e5ae73199575
< 3.2.0
MEDIUM 4.7 The OneLogin SAML SSO plugin for WordPress is vulnerable to open redirection in versions up to, and including, 3.1.2. T… wordfence
dd27aeb9-4257-4b15-8f14-8a8c89522c32
< 1.1.6
MEDIUM 4.7 The QuBotChat plugin for WordPress is vulnerable to Self-Based Cross-Site Scripting in versions up to, and including, 1.… wordfence
daf8e0ca-abe7-4243-8921-ff5a6f88cfcf
< 1.7.29
MEDIUM 4.7 The WP YouTube Lyte plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.7.28. Th… wordfence
d93a4901-3fbd-40b2-af0b-501fa837424a
< 2.0.1
MEDIUM 4.7 The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized access in versions up to, and inclu… wordfence
d7dcc31c-9255-4bd2-92b4-ce9a1df5f24c
< 3.6.1
MEDIUM 4.7 The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalati… wordfence
CVE-2026-1277
< 1.12.2
MEDIUM 4.7 The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to… nvd
caf0d33d-4bfd-460f-b21c-df36b1452b2e
< 2.14.4
MEDIUM 4.7 Reflected Cross-Site Scripting (XSS) vulnerability in Code Snippets plugin <= 2.14.3 at WordPress via &orderby vulnerabl… wordfence
cabe5d20-710c-47d7-a5a3-562287ab5706
< 3.0.0
MEDIUM 4.7 Cross-Site Scripting (XSS) vulnerability discovered in Yasr – Yet Another Stars Rating WordPress plugin (versions <= 2… wordfence
ca12d05f-23f4-44e4-b513-a0452a170130
< 7.0.00
MEDIUM 4.7 The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versi… wordfence
c997dfc8-7cec-4636-9fe4-df1fb6436082
< 5.0.0
MEDIUM 4.7 The Guest posting / Frontend Posting / Front Editor – WP Front User Submit plugin for WordPress is vulnerable to Open … wordfence
c7c1dc51-47ca-4b2f-9ff9-275bd8b1c106
< 1.12.2
MEDIUM 4.7 The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to… wordfence
c37d8218-6059-46f2-a5d9-d7c22486211e
< 4.1.5
MEDIUM 4.7 The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SHORTPIXEL_DEBUG p… wordfence
c10286fe-2fdf-4946-b7bb-a2b16f93abb0
< 2.5.7
MEDIUM 4.7 The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vuln… wordfence
bccceb2d-2087-4ee6-8118-eb3fb53654dc
< 1.3.3
MEDIUM 4.7 The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files… wordfence
bc112db6-fb80-4edd-be36-4aae81a656e4 MEDIUM 4.7 The GlobalQuran plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. … wordfence
b926243c-ed12-4afe-ac72-932d4d871019 MEDIUM 4.7 The Short URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.8. … wordfence
b6db6736-4629-47b7-976a-f81335430119
< 2.0.1
MEDIUM 4.7 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Reflected Cross-Site… wordfence
b3ea5e75-9b6a-4710-bb2c-458c2a924bb0
< 0.3
MEDIUM 4.7 The ThinkIT WP Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 0.3. Thi… wordfence
b1791d41-cdfe-4918-8351-2108302241c1
< 2.3.3
MEDIUM 4.7 SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to… wordfence
b15b08e1-0aa7-49a3-9a08-bbc48f13260c
< 1.3.5
MEDIUM 4.7 The Wp Edit Password Protected – Create Password Protect Pages & Design Password Protected Form plugin for WordPress i… wordfence
b0ab311f-26c1-4165-80bc-512348fcc0c0 MEDIUM 4.7 The FL3R FeelBox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.1.… wordfence
ae13e0eb-b77c-4e9f-a5aa-caf2c67db7bc
< 1.0.23
MEDIUM 4.7 The Responsive Filterable Portfolio plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up… wordfence
abe6366a-3729-474f-8920-b5ed2eeab906
< 6.11.2
MEDIUM 4.7 The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Reques… wordfence
← Prev 1264 1265 1266 1267 1268 1269 1270 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top