🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 416 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ad953bc7-5747-4936-b702-37386299369e
< 1.1.2
HIGH 7.1 The Pop-up plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the function … wordfence
aae57fed-1003-4b3a-8489-cfc85c250a04
< 1.1.4
HIGH 7.1 The Videos on Admin Dashboard plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.1.4 due to… wordfence
aacd4a33-499d-4630-a0fb-8a1acfcfb7dd HIGH 7.1 The WP Code Highlight.js plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.… wordfence
aa5c23ed-7239-40e1-a795-1ae8d4c2d6c8
< 2.7.3
HIGH 7.1 The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing … wordfence
aa2bd74a-563a-4a2d-b1d7-b3678db82b00
< 6.0.10
HIGH 7.1 The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple paramet… wordfence
a7e24341-b085-4412-aa7b-42712cd94f35
< 1.1
HIGH 7.1 The Simple Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in version… wordfence
a7c32efa-1872-4302-a947-dc0005080e55 HIGH 7.1 The Citizen Space plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘path’ parameter in v… wordfence
a72e60d7-6019-4d88-88f4-22ec4dedbdd8
< 0.1.6.7
HIGH 7.1 Multiple cross-site scripting (XSS) vulnerabilities in pages/3DComplete.php in the WooCommerce SagePay Direct Payment Ga… wordfence
a4c0180e-e3f0-42a3-9f97-735b22c1260c
< 1.9.9.5.2
HIGH 7.1 The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file de… wordfence
a1eda885-7e10-4294-9748-5359efd51754 HIGH 7.1 The Mega Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the vc_s… wordfence
a0413f69-7251-4c01-b2e0-c8638d797652 HIGH 7.1 The AMP ToolBox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in vers… wordfence
9ed8e24d-6bd0-4638-9031-997ce2228fad
< 2.1.2
HIGH 7.1 The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.… wordfence
9df45c8e-c040-4031-9c51-4c43d12f08b0
< 4.7.20
HIGH 7.1 Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing iss… wordfence
9dd71a06-b3b5-431a-b6da-3b7db3a3907c
< 2.5.1
HIGH 7.1 The Plugin Central plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘file' and 'name' para… wordfence
9cfbafce-ba3b-477f-ad8d-ca4e57332f0b
< 1.7.2
HIGH 7.1 The WangGuard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions be… wordfence
9b90bf09-639c-497c-a58e-3972250db1e4 HIGH 7.1 The Manage Upload Limit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the upload_limit parame… wordfence
9a85cad9-bcb8-417d-a80b-3334a3ef77a2 HIGH 7.1 The Easy Filtering plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
9a475017-ef45-4614-bdc6-ddd619b8caf3
< 3.4.1
HIGH 7.1 The WP-Stateless – Google Cloud Storage plugin for WordPress is vulnerable to unauthorized loss of data due to a missi… wordfence
99721c3e-cddf-4709-aef9-92bb42e43f83
< 2.1
HIGH 7.1 Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the Wo… wordfence
98527ebf-26a3-4900-84b5-3d2245783e8e HIGH 7.1 The BuddyPress BP Gallery Plus plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includi… wordfence
97fc00d0-ca3d-462a-ac9f-bfac4c882cc1
< 1.5.1
HIGH 7.1 Cross-site scripting (XSS) vulnerability in wlcms-plugin.php in the White Label CMS plugin 1.5 for WordPress allows remo… wordfence
97f6e03b-19ac-450b-9895-45f7d5328907
< 6.1.3
HIGH 7.1 Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin … wordfence
95c8722e-07c3-4728-8723-4d4a6188fe5e
< 1.2.6
HIGH 7.1 The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing cap… wordfence
943668eb-0185-4029-9459-f99141bf84cf
< 3.1.2
HIGH 7.1 The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is… wordfence
9269e358-83cb-42e7-a30d-79f1504e576c
< 2.8.3
HIGH 7.1 Multiple cross-site request forgery (CSRF) vulnerabilities in the Facebook Like Box (cardoza-facebook-like-box) plugin b… wordfence
← Prev 413 414 415 416 417 418 419 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top