ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 800 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ddc1aedb-e64f-4b61-a247-c3cdc731f001
< 1.10.6
MEDIUM 6.1 The Exit Notifier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg w… wordfence
ddb979b5-8fd6-41ed-a535-ad6646a14677
< 2.0.14.5
MEDIUM 6.1 The ListingPro theme before v2.0.14.5 for WordPress has Reflected XSS via the What field on the homepage. wordfence
ddb6263e-1f03-48b5-b319-e023e526a4ad MEDIUM 6.1 The WP FPO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.… wordfence
ddad22fb-0b41-4c8f-b35d-21692e3a9908 MEDIUM 6.1 The Social Media Sharing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
dd979c94-f6e7-4edd-b2c5-0880ed13e9b0
< 4.13.1
MEDIUM 6.1 The YITH WooCommerce Product Add-Ons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up… wordfence
dd9548bd-4064-4ef8-9f35-5d05bba7f190 MEDIUM 6.1 The Theme My Ontraport Smartform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
dd93ef08-b4cf-4e50-b2db-88b101b146f4
< 7.1.5
MEDIUM 6.1 The Enfold - Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versi… wordfence
dd8f348d-07ff-480d-bcc1-fb39aead1b1d MEDIUM 6.1 The Folo theme for WordPress is vulnerable to Cross-Site Scripting vai the 'jplayer.swf' file due to insufficient input … wordfence
dd86d46d-f418-4f01-9416-ee2baba08d72 MEDIUM 6.1 The Bitcoin / AltCoin Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripti… wordfence
dd847af9-ad71-4171-adb1-f38e2acf16d5 MEDIUM 6.1 The Invisible Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
dd805cb5-45ce-4213-b313-d9e300527265
< 1.5.7
MEDIUM 6.1 The VOD Infomaniak plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
dd7db465-ebeb-477b-b6c8-a9b89ba2372b
< 4.8.5
MEDIUM 6.1 The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Open Redirection via the '_redirect_to ' parameter in … wordfence
dd7d3afd-6648-4ffb-85a9-cd5a6096963e
< 8.0.7
MEDIUM 6.1 The Zip Recipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions u… wordfence
dd799c2a-e26b-4362-8f7f-dbcbfe3bfe10 MEDIUM 6.1 The UDesign Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
dd4d7c44-890c-4560-b637-cdc0ca00de31
< 13.05
MEDIUM 6.1 Open redirect vulnerability in invite.php in the WP Symposium plugin 13.04 for WordPress allows remote attackers to redi… wordfence
dd3bfdc0-8e1b-49e9-b800-cb2dde2d5acb
< 1.0.24
MEDIUM 6.1 The Booking Calendar Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several param… wordfence
dd3a198c-7c24-45b1-95a7-eb16472a51e2
< 4.9.67
MEDIUM 6.1 The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via U… wordfence
dd15c7c8-6538-4443-a409-0d34ff893963
< 1.3.13
MEDIUM 6.1 The Koko Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg … wordfence
dd1335cd-dc12-4699-9c57-900ba50aeef5
< 9.6.1
MEDIUM 6.1 The XStore theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 9.6.1 due to insufficie… wordfence
dd112c38-e6c1-435c-b62d-8fab06e90eb6 MEDIUM 6.1 The videowall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page_id' parameter in the 'i… wordfence
dd108f90-7afc-43e1-86d4-939c1c25fb2d MEDIUM 6.1 The IP Blacklist Cloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter … wordfence
dd052762-5bd3-4008-b6b9-aca7be1151c2
< 1.1.2
MEDIUM 6.1 An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-aj… wordfence
dcfe3035-db43-499f-b09f-be528725b1d8
< 1.0.5
MEDIUM 6.1 The Easy Digital Downloads (EDD) Shoppette theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10… wordfence
dcfca0fe-5b15-4276-896a-9ad12b9a9478
< 2.1.4
MEDIUM 6.1 The Easy Digital Downloads (EDD) Amazon S3 extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.… wordfence
dcf4a063-6954-4414-a2ee-d92f4192f4d4 MEDIUM 6.1 Multiple cross-site request forgery (CSRF) vulnerabilities in the Mikiurl Wordpress Eklentisi plugin 2.0 and earlier for… wordfence
← Prev 797 798 799 800 801 802 803 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top