πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1270 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3529044f-c3d8-4370-8ba5-9df0fb71ab3c
< 2.6.6
MEDIUM 4.7 The Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin … wordfence
33f1d8b9-3561-4347-8267-8c36d4c9071f
< 6.11.4
MEDIUM 4.7 The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-S… wordfence
32028952-ccd7-48f6-87ce-0924f40d99ae
< 3.7.1
MEDIUM 4.7 The Meta for WooCommerce plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.7.0… wordfence
30e67229-f3b6-43e4-a0c4-2e4392f4bec5
< 1.3.6
MEDIUM 4.7 The WP Gravity Forms FreshDesk Plugin plugin for WordPress is vulnerable to Open Redirect in all versions up to, and inc… wordfence
221f9cbb-7988-4671-8f14-da3e63c280e6
< 3.3.19.1
MEDIUM 4.7 An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via … wordfence
221872e2-7929-4fba-8a57-7d9fd73a76db
< 3.0.1
MEDIUM 4.7 WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add user… wordfence
1f092dae-e298-42e3-b494-fc7b7669b300
< 4.4.4
MEDIUM 4.7 The All In One WP Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab p… wordfence
1d430b33-1607-46b3-8780-ac5cfbb7d6ec
< 1.1.46
MEDIUM 4.7 The Event Calendar WD plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.4… wordfence
1a5ac5f9-aaf4-4a7f-9d1d-fc8f5e632c21 MEDIUM 4.7 The Favicon My Blog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
1646f96c-f0f4-433a-ac5e-04c1c251972d MEDIUM 4.7 The CryoKey plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜ckemail’ parameter in all … wordfence
125e11a3-c497-484e-940b-2bcdf7f2c1ab
< 1.15.3
MEDIUM 4.7 Insufficient Input Validation in the search functionality of Wordpress plugin Share-one-Drive prior to 1.15.3 allows una… wordfence
0ec8a72e-0153-4c2b-bdda-c6474cc2aadb
< 2.5.10
MEDIUM 4.7 The bbPress plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.5.9 due to in… wordfence
0c944e08-1b70-4b56-80eb-f588c0fab5b6
< 3.4.2.14
MEDIUM 4.7 The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to St… wordfence
04cd8da4-9da3-4c80-a77e-c2f792391593
< 2.5.1
MEDIUM 4.7 The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due… wordfence
047cd34e-f2a1-4643-a1c5-3ead926b83ca
< 8.1.5
MEDIUM 4.7 The iThemes Security plugin for WordPress is vulnerable to open redirection in versions up to, and including, 8.1.4. Thi… wordfence
e635dfb3-002d-4197-b14a-0136a1990a75
< 1.8.3
MEDIUM 4.6 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
7e42954c-1ae3-41ef-8dd3-16e5820aa36f
< 3.5.2
MEDIUM 4.6 moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other product… wordfence
6a6eb430-cf86-4e13-a4f7-173fada9fddf
< 3.8.1
MEDIUM 4.6 The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stor… wordfence
5d7bcd71-e299-47fe-a749-e72c49b8129e
< 7.2.1
MEDIUM 4.6 The BuddyPress plugin for WordPress was vulnerable to authorization bypass due to a misconfiguration in how the plugin h… wordfence
5779914a-a168-4835-8aea-e0ab2b3be4f6
< 3.4
MEDIUM 4.6 The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized modification of … wordfence
4b6f9700-eb29-4391-845c-58e1a2327b0b
< 3.7.30
MEDIUM 4.6 In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php cou… wordfence
ffd97ee6-1858-4e8b-bd91-1c509cfa5a15
< 1.6.9
MEDIUM 4.4 The Accounting for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… wordfence
ffc92f28-02bd-48b3-b803-b67feab74db2
< 5.3.6
MEDIUM 4.4 The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
ffbb85c5-e949-4c0f-8c02-2c022b802e05
< 1.2.3
MEDIUM 4.4 The Pagination by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
ffaefd79-57a7-43b8-af1c-e108567eba67
< 1.0.7
MEDIUM 4.4 The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
← Prev 1267 1268 1269 1270 1271 1272 1273 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top