πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1269 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
69a6d8a5-0325-4436-8034-8353d2a68831
< 5.4.20
MEDIUM 4.7 The B2Bking plugin for WordPress is vulnerable to Open Redirect in all versions up to 5.4.20 (exclusive). This is due to… wordfence
696495c5-c8f8-4790-af89-1ee911767b1b MEDIUM 4.7 The Solutions Ad Manager plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.0.0… wordfence
6781dcc5-db95-43ca-9042-a3c05414b7e6 MEDIUM 4.7 The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to Sensitive Information Exposure in all… wordfence
65614ad8-cec6-4768-a3f2-c550254bd418
< 1.5.3
MEDIUM 4.7 The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Open Redirect in all versions up to, and… wordfence
62b809dc-4089-4822-8aeb-7049fcfe376e
< 3.1.5
MEDIUM 4.7 The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress i… wordfence
5fe374ff-85eb-4285-8d51-71e9275613cc
< 1.0.13
MEDIUM 4.7 The Core Web Vitals & PageSpeed Booster plugin for WordPress is vulnerable to Open Redirect in versions up to, and inclu… wordfence
5c8404d2-7b37-40df-b756-328f827f273d
< 1.1.5
MEDIUM 4.7 The Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnera… wordfence
5c24ee66-7b57-4e4c-bbb5-0451fc24ce4b
< 8.0.7
MEDIUM 4.7 The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
5adf03ff-5b87-4ed3-b7ec-b89bc814aba6
< 4.9.4
MEDIUM 4.7 The Spiffy Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜page’ parameter in… wordfence
59926d18-215e-4de3-acf2-19870026a13f
< 1.15.3
MEDIUM 4.7 The Lets-Box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions before 1.15.3 due to insuf… wordfence
55a57b5f-2f87-4060-b1c2-77086f695dda
< 6.8.1
MEDIUM 4.7 The Simple:Press plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sforum_[md5 hash of the W… wordfence
4bd91c8a-f851-4810-b99e-aadae460091f MEDIUM 4.7 The Dynamic Pricing & Discounts Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
48d0e0e0-81db-46ef-ba64-daa2a4079b79
< 3.3.0
MEDIUM 4.7 The Yoast SEO plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.2.5 due to … wordfence
4126d452-65a9-48f5-a3f5-5be1b8fff80c
< 2.9.31
MEDIUM 4.7 The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in t… wordfence
40f7fd0f-4383-44c4-8c49-f1c25e1e3681
< 3.3
MEDIUM 4.7 The Meta Tag Manager plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.2. This… wordfence
40a08542-5e2e-4689-b26f-99a1350185cc
< 3.1.16
MEDIUM 4.7 The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npB… wordfence
4071c361-3a68-49b7-ac50-4b32e2e1c3ff
< 3.6
MEDIUM 4.7 Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordP… wordfence
3f937290-fa45-4ce0-84f0-a42c83cd3bdf MEDIUM 4.7 The DT Chocolate theme for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.0. This is due t… wordfence
3c74ea5e-e25a-4b78-b04c-ed66992d4d80
< 6.4.9.6
MEDIUM 4.7 Multiple cross-site scripting (XSS) vulnerabilities in the Google Analyticator plugin before 6.4.9.6 for WordPress allow… wordfence
3c2bddb3-2b23-4a75-abe2-db787441a1b2 MEDIUM 4.7 The DancePress (TRWA) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
3aeb5e01-0993-4628-8165-b27470332e34
< 1.5.6
MEDIUM 4.7 The plugin KB Support – WordPress Help Desk versions up to 1.5.5 are vulnerable to Cross-Site Scripting. The vulnerabi… wordfence
3a1782c3-ae0b-42f1-aa5e-dabfa2a5bbcd
< 3.3
MEDIUM 4.7 The WPO365 | MICROSOFT 365 GRAPH MAILER plugin for WordPress is vulnerable to Open Redirect in all versions up to, and i… wordfence
3a11216c-868c-4dd9-b6d5-2a772d7d303e
< 2.7.2
MEDIUM 4.7 The Comment Press plugin for WordPress is vulnerable to Cross-Frame Scripting in versions up to, and including, 2.7.1. T… wordfence
390e9c30-e4c0-474d-9915-dd46f5464cea
< 9.87.1.0
MEDIUM 4.7 The VK All in One Expansion Unit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜$_SERVE… wordfence
38ccaa81-77ec-46f2-9bec-d74fa2e093f3
< 1.9.218
MEDIUM 4.7 The WS Form LITE plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.9.217. This all… wordfence
← Prev 1266 1267 1268 1269 1270 1271 1272 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top