🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 799 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ded8f958-ed2a-43ab-8688-9f6d16515469 MEDIUM 6.1 The Third Party Cookie Eraser plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
ded4b93f-fd90-4803-9d20-3109512b1a24 MEDIUM 6.1 The Image Tag Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'default_class’ par… wordfence
ded05261-36f2-4414-b30a-7467b0c79938 MEDIUM 6.1 The WP Fountain WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] … wordfence
deba9cd0-2c7e-4789-8499-977c694aba8b
< 1.6.21
MEDIUM 6.1 The Events Made Easy plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting via… wordfence
deb6821e-93ff-4636-912b-887deba59577
< 3.4.7
MEDIUM 6.1 Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.7 for WordPress allows an attacker to in… wordfence
dead051c-f28f-4859-b0ba-b27a8d6c9335 MEDIUM 6.1 The Crypto and DeFi Widgets – Web3 Cryptocurrency Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Sit… wordfence
de957e90-5758-46f3-90f8-521b47d247ff
< 1.2.1
MEDIUM 6.1 The Sender by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
de8abfac-f25e-41a4-8e94-ab01b105f3b4 MEDIUM 6.1 The Shabbos and Yom Tov plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
de897025-e2e0-4e21-9c58-db2c20d5d3f9 MEDIUM 6.1 The Key4ce osTicket Bridge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
de7be653-4d5b-4cbe-ad9c-6c2748f533bb
< 2.08
MEDIUM 6.1 The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t… wordfence
de7b0d72-9227-4ecd-a88f-a7d04b592f59 MEDIUM 6.1 The Rio Video Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
de6d07f0-6e69-4b6d-98ee-128117f0b822 MEDIUM 6.1 The Scanventory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
de5feed6-ef1b-4e06-9bd0-145292f613b6 MEDIUM 6.1 The Local Shipping Labels for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all ve… wordfence
de5d5ffc-e76a-4ea9-be68-9ca5f847a363
< 2.0
MEDIUM 6.1 The All 404 Pages Redirect to Homepage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple pa… wordfence
de58a0d1-42d2-46d7-a8a5-6b86b438b326 MEDIUM 6.1 The World Cup Predictor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
de523bc3-3c22-4632-8f14-2f9098cb4f28
< 3.14.0
MEDIUM 6.1 The Newspack Newsletters plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.13.… wordfence
de4f4064-cb72-4b67-b8af-0b2cec5a53d0 MEDIUM 6.1 The WP Service Payment Form With Authorize.net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… wordfence
de388a39-8966-4b08-a4d2-dbbcd0459c23 MEDIUM 6.1 The Post Thumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
de331d1d-b2f8-4cc6-a998-779595eca70c
< 1.1.16
MEDIUM 6.1 The WP Responsive Tabs horizontal vertical and accordion Tabs plugin for WordPress is vulnerable to Reflected Cross-Site… wordfence
de20d896-1493-43ed-8e0c-c686bf2b32d6
< 3.10.5
MEDIUM 6.1 The Master Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
de159b3e-b456-4b36-ad44-41d3595b53a8
< 1.4.0
MEDIUM 6.1 The Isolved Talent Acquisition plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
ddff1a95-64f9-4076-a81a-cdda04106c46 MEDIUM 6.1 The Disconnected theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
ddd2c0c2-49b5-4745-9e52-d0ae6b997640 MEDIUM 6.1 The WP Design Maps & Places WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the filename parameter … wordfence
ddca65fa-0744-4b2a-808c-a913586edc60 MEDIUM 6.1 The WPGlobus Translate Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
ddc889bf-8062-4a2c-9d50-d1c76a3c3386
< 1.0.1
MEDIUM 6.1 The Emag Marketplace Connector plugin 1.0.0 for WordPress has reflected XSS because the parameter "post" to /wp-content/… wordfence
← Prev 796 797 798 799 800 801 802 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top