πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 414 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f4969c74-7378-46cb-8028-91db91c4ae7e HIGH 7.1 The ntp-header-images plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
f1d2015b-86e8-4d0f-b095-f3917480ff15
< 18.2.1
HIGH 7.1 Helper plugins packaged with Bridge theme possess an Open Redirect vulnerability, allowing a malicious actor to create l… wordfence
ee2c5df2-250a-4e35-9219-2630d8d9253a
< 3.1.3
HIGH 7.1 WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a fr… wordfence
ec864830-2c8b-4ae4-9c45-3624d0be7d24
< 2.68
HIGH 7.1 The Disqus Comment System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the User-Agent HTTP H… wordfence
ec2edcdf-3a0c-40bc-8b33-1ad15cad5acb
< 1.4.18
HIGH 7.1 Multiple cross-site scripting (XSS) vulnerabilities in the Welcart plugin before 1.4.18 for WordPress allow remote attac… wordfence
e7b84f9b-2b01-4e25-907d-4be735594d07 HIGH 7.1 Cross-site scripting (XSS) vulnerability in get.php in the WP Microblogs plugin 0.4.0 and earlier for WordPress allows r… wordfence
e64a688c-c150-4b10-81ef-bbe7f6dd1b8e
< 1.3.4
HIGH 7.1 The Integration for Contact Form 7 and Salesforce plugin for WordPress is vulnerable to Open Redirect in versions up to,… wordfence
e63da1a9-235d-4a6e-95e0-ac4488dc9eff HIGH 7.1 The WP Site Protect plugin for WordPress is vulnerable to Cross-Site Scripting via the 'password' parameter in versions … wordfence
e10db126-a22e-4e15-a868-6fd9172fa805
< 3.2.1
HIGH 7.1 Cross-site request forgery (CSRF) vulnerability in the Login Widget With Shortcode (login-sidebar-widget) plugin before … wordfence
e0ec0027-2792-4069-b413-8fdd951f5fe7
< 1.15.36
HIGH 7.1 The Form Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via hidden field values in all versions… wordfence
e056dcb5-a66b-4cd3-9a73-37f226015e09
< 2.4.42
HIGH 7.1 The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post content in all ver… wordfence
de918177-5901-40ed-a936-c212cdcf940d
< 1.5.3.9
HIGH 7.1 The P3 (Plugin Performance Profiler) plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.5.3… wordfence
db6995d1-8060-40cb-9e35-2baea4e39072 HIGH 7.1 The Floating Tweets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versi… wordfence
db4b92ba-b98f-4e9d-bd1e-75bf89d83977
< 1.2.5
HIGH 7.1 The SVGator – Add Animated SVG Easily plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
d951e6b4-986a-400a-ab28-066a4ea5cbca
< 6.1
HIGH 7.1 The Quick Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting via the 'qcfname4' parameter in versio… wordfence
d874f9d7-c532-467d-9e3d-9529dd5bdc47
< 2.9.11
HIGH 7.1 The Pods plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10.2. Th… wordfence
d7edb3be-ffa9-4e80-addf-5e5aca6050ef
< 3.0.18
HIGH 7.1 The Pie Register plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 3.0.18 due to insufficien… wordfence
d5d77105-19a8-40eb-8a9c-aa519a757a8d
< 1.80
HIGH 7.1 The 1003 Mortgage Application plugin for WordPress is vulnerable to arbitrary file download in versions up to, and inclu… wordfence
d4491b89-2120-4edb-a396-e45ba09b3b99
< 4.4
HIGH 7.1 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data du… wordfence
d2ea39fb-5adc-4666-95da-b25024ca32d6
< 3.5.5
HIGH 7.1 The Count per Day plugin for WordPress is vulnerable to Cross-Site Scripting via the 'limit' parameter in versions up to… wordfence
d097d918-04dc-4291-bb82-3f5cc8eea158
< 1.4.2
HIGH 7.1 The WP DS FAQ Plus plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before … wordfence
cf48ad3b-9b3a-4052-bacf-52a729d62365
< 1.17.0
HIGH 7.1 The Link Checker plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1.… wordfence
cf037a61-7e4d-4c20-b868-2fa78950bad3
< 1.3.3
HIGH 7.1 The "Golo - City Travel Guide WordPress Theme" theme for WordPress is vulnerable to Reflected Cross-Site Scripting via t… wordfence
cc8e2524-b77d-447e-aea9-0dfef33809f9
< 1.10
HIGH 7.1 The Timely All-in-One Events Calendar plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters … wordfence
cb075e85-75fc-4008-8270-4d1064ace29e
< 1.9.7
HIGH 7.1 The Bricks theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.6.1. This… wordfence
← Prev 411 412 413 414 415 416 417 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top