πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1268 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a2e493cf-d022-404d-a501-a6671e6116f4
< 3.23
MEDIUM 4.7 The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
a224e745-f9c7-4ca6-b656-e94862b1dc57
< 2.0.36
MEDIUM 4.7 The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions u… wordfence
a092266b-bd7f-424d-b8c4-d79e4811e6c9 MEDIUM 4.7 The Responsive Column Widgets plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.2.… wordfence
a06bba7f-0259-4b87-b3fe-6ad8318fda7d
< 3.1.15
MEDIUM 4.7 The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
9bb026a4-02b1-4422-8c78-9983c49df43e
< 4.1.1.1
MEDIUM 4.7 The Events Calendar plugin for WordPress is vulnerable to an open redirect vulnerability in versions before 4.1.1.1. Thi… wordfence
9963e0f8-600c-4b1f-935d-4ac1f967698f
< 1.4.32
MEDIUM 4.7 The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notificati… wordfence
97c68df7-69fd-4817-9473-3d3e1fd6d348
< 2.7.0
MEDIUM 4.7 The WooCommerce Product Enquiry plugin for WordPress is vulnerable to Self-Cross-Site Scripting via the enquiry form fie… wordfence
95d68a5d-4d0b-4030-a80a-ada31b118af2
< 3.119.0
MEDIUM 4.7 The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
95d4fbf6-e21a-48db-bfb3-32fc9116afa0
< 1.6.12
MEDIUM 4.7 The Parcel Pro plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.6.11. This is… wordfence
938e8f54-56f0-4066-bc78-ebfc2abe0743 MEDIUM 4.7 The Flash player widget plugin for WordPress is vulnerable to Content Spoofing in versions up to, and including, 1.3. Th… wordfence
92928f3b-cf45-4735-87d7-040afa4857f4
< 3.5.0
MEDIUM 4.7 The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to Server-Side Re… wordfence
8db736fb-cd6c-4a52-9dd3-eefd0a8d9267
< 6.5.0.5
MEDIUM 4.7 The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to St… wordfence
8a6ca886-de4c-4d45-a934-3e90378e7eb3
< 4.4.3
MEDIUM 4.7 The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter… wordfence
81f9a4c6-971f-4f6d-8bb1-e97bf75cf8d3
< 3.3.7
MEDIUM 4.7 The Order Tracking Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the order status parameter … wordfence
81eb8963-548f-4e94-83bd-266a19c09aab
< 2.0.4
MEDIUM 4.7 The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
7d047fe7-bf00-4f93-91d2-c5da41664bfc
< 2.13.5
MEDIUM 4.7 The Age Gate plugin for WordPress is vulnerable to Open Redirects in versions up to, and including, 2.13.4 via the '_wp_… wordfence
7cc86970-7e63-47d0-9971-ddd0fc992a5a
< 1.7.15
MEDIUM 4.7 The AddToAny Share Buttons plugin for WordPress is vulnerable to Host Header Injections in versions up to, and including… wordfence
7bd64a61-3bc7-4d0f-b3bc-1988e75cf749
< 1.2.9
MEDIUM 4.7 The WP Gravity Forms Zoho CRM and Bigin plugin for WordPress is vulnerable to Open Redirect in all versions up to, and i… wordfence
79a574c4-1faf-4572-801c-00b50923a669
< 1.5.6
MEDIUM 4.7 The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… wordfence
7894a19c-b873-4c5b-8c82-6656cc306ee2
< 2.2.5
MEDIUM 4.7 The Popup More Popups, Lightboxes, and more popup modules plugin for WordPress is vulnerable to Local File Inclusion in … wordfence
72b14197-560a-4dc2-9c23-a250f51dc51e
< 3.7.25
MEDIUM 4.7 WordPress through 4.9.1, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to cond… wordfence
6e77d240-475d-41a2-9b88-1332fc60b72d
< 3.3.17
MEDIUM 4.7 The My Calendar plugin for WordPress is vulnerable to Open Redirection in versions up to, and including, 3.3.16. This ma… wordfence
6b5d31c5-0516-4089-9867-2922670e1b04
< 1.9.16
MEDIUM 4.7 The Gravityforms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting up to, and including, 1.9.15.11 du… wordfence
6b36fcc5-1f09-43b9-8877-7af6c7652db7
< 1.5.3
MEDIUM 4.7 The White Label CMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
69f54737-4b0f-49ba-a331-1b252a5e45cb
< 2.9.7
MEDIUM 4.7 The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in… wordfence
← Prev 1265 1266 1267 1268 1269 1270 1271 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top