🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 418 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
65db2345-4b55-466c-b148-7d954de96a87
< 1.7.5
HIGH 7.1 Cross-site scripting (XSS) vulnerability in fs-admin/wpf-add-forum.php in the ForumPress WP Forum Server plugin before 1… wordfence
637a53b5-6d2f-4671-8126-f218c3ca73de
< 1.9.9.5.2
HIGH 7.1 The WPLMS plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all … wordfence
6309258e-e4fc-4edf-a771-2d82a9a85a5c
< 3.8
HIGH 7.1 The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery due … wordfence
62dacee5-9b55-4d0e-aa35-d97a1666f9e1
< 1.5.1
HIGH 7.1 Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordP… wordfence
6290c671-c8e5-4cc3-a233-9fed584ca02f
< 1.5.1
HIGH 7.1 There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1 via search_tit… wordfence
62128061-1ecc-484c-a054-4925f9ac6105
< 1.2.5
HIGH 7.1 Cross-site scripting (XSS) vulnerability in the Unconfirmed plugin before 1.2.5 for WordPress allows remote attackers to… wordfence
61d3f1f4-4cb9-4dd2-bda7-d08b2ccdbcba
< 2.15
HIGH 7.1 A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with bas… wordfence
6173d307-9917-4d76-b6bf-d5646b9e33d6
< 2.4.4
HIGH 7.1 The WP Activity Log plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘notice’ parameter … wordfence
6156a351-d681-4661-9131-62251b715a94
< 1.3.65
HIGH 7.1 The Role Scoper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versi… wordfence
5d9ab83f-6d0b-4fe4-a121-87b09dcc0953 HIGH 7.1 The Cart2Cart: Magento to WooCommerce Migration plugin for WordPress is vulnerable to unauthorized modification of data … wordfence
5d380b66-675e-451d-a7e3-4efe1fbd08b2
< 10.1.3
HIGH 7.1 The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulne… wordfence
5c637882-1854-4502-9907-88053d141cfc
< 1.22
HIGH 7.1 Cross-site scripting (XSS) vulnerability in wp-cumulus.php in the WP-Cumulus Plug-in before 1.22 for WordPress allows re… wordfence
5b333a3d-e416-42aa-9722-5406df0a64b3
< 3.6.6
HIGH 7.1 The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhoo… wordfence
5b2db550-c1cf-4c5b-91b1-349da3fd859d HIGH 7.1 The MSMC Redirect After Comment plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Sc… wordfence
598e2c2e-7dd5-435e-a366-6c7569243f2a
< 2.2.3
HIGH 7.1 The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to Open Redirect in all versions up to, and inc… wordfence
596d1083-2030-41f0-92d4-82e98bf07331
< 1.04
HIGH 7.1 Cross-site scripting (XSS) vulnerability in skysa-official/skysa.php in Skysa App Bar Integration plugin, possibly befor… wordfence
58a83ec8-e294-4fb6-9f1a-19562b2e499d
< 2.1.10
HIGH 7.1 The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via … wordfence
588afcb3-9bba-4514-ac58-a53bcc3521c3 HIGH 7.1 The Blrt WP Embed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
57896fa8-9360-41e8-a60e-8b95d01c25ac
< 5.7.0
HIGH 7.1 The WP Cleanfix plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a miss… wordfence
52c7edcc-d8dd-401a-9d36-e395fa7189bf
< 16.01
HIGH 7.1 The WP Symposium Pro plugin for WordPress is vulnerable to Cross-Site Scripting via the 'wpspro_country' parameter in ve… wordfence
5294af95-e85f-4425-9c4b-0a92dfac4bd1 HIGH 7.1 The Digital Climate Strike WP for WordPress contains a malicious redirect in versions up to, and including, 1.0.0. This … wordfence
52383075-2d39-4fd9-8319-15a5354ff25f
< 1.8.8
HIGH 7.1 The MP3-jPlayer plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1.8… wordfence
5222ce69-ac9f-4bb0-9832-8cdff1f8b078
< 3.19.15
HIGH 7.1 The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i… wordfence
518771c1-b52b-47b7-99f1-4f40115ba4cf
< 2.0.15
HIGH 7.1 The Pie Register plugin for WordPress is vulnerable to Cross-Site Scripting via the 'notice' parameter in versions befor… wordfence
501aed34-537b-4d35-a04f-a984297adb39
< 0.7.25
HIGH 7.1 The Job Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘jobman-rating’ paramet… wordfence
← Prev 415 416 417 418 419 420 421 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top