🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 801 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
dce917b5-d4d8-4d85-a249-2446386dbef6 MEDIUM 6.1 The Twitter Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
dce89625-d00e-4f96-a7c4-2a215c1dfdeb MEDIUM 6.1 The AB Categories Search Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
dce7ec6a-aded-48eb-a682-a7fe7f07082b MEDIUM 6.1 The Sala theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1.3 due… wordfence
dce0e29f-d846-496b-a9fb-2f57cc352970
< 2.6.0
MEDIUM 6.1 The ChillPay WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
dcdf22be-8af4-4596-b138-67ebfd04c06d
< 0.4.6
MEDIUM 6.1 The GTmetrix for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter … wordfence
dcdb5d23-b9fe-495b-8431-f82f22813531
< 1.1.20
MEDIUM 6.1 The iQ Block Country plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ipaddress’ parame… wordfence
dcabc099-ef35-4dcd-ba53-ef20a0ad1abc
< 1.2.5
MEDIUM 6.1 The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication fo… wordfence
dca8f186-c58a-40bc-b1d1-b29bcf4631c5
< 4.0
MEDIUM 6.1 The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter. wordfence
dc949922-7bfa-4704-9038-cf4b5262f864
< 1.1.2
MEDIUM 6.1 The WIP Incoming Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
dc948f30-2fc2-40dd-878e-28e0eac857c7 MEDIUM 6.1 The Attachments Handler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up … wordfence
dc92b20a-fb9b-477c-8fe4-68897c1fd07e
< 3.4.17
MEDIUM 6.1 The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
dc8f46a4-b086-440c-809f-1a3db44125f1
< 3.0.16
MEDIUM 6.1 The Animator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.0.… wordfence
dc8dc895-8caa-4a37-80f0-3a5516c25dfe
< 1.0
MEDIUM 6.1 The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions… wordfence
dc8c0726-82b7-487e-ba9e-7adc892979d2
< 3.0.13
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the BackWPup plugin before 3.0.13 for WordPress allows remote attackers to i… wordfence
dc841e7d-a815-4ed0-b5ec-6ce76fb859c5
< 3.2.0
MEDIUM 6.1 The WP-HR Manager: The Human Resources Plugin for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site S… wordfence
dc4003f8-7250-435b-99b1-c45d80e27ce1
< 8.1.2
MEDIUM 6.1 The Mollie Payments for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up … wordfence
dc322548-ffc9-4246-9835-fcc5705cef3f
< 4.1.1
MEDIUM 6.1 The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting t… wordfence
dc277e7c-86ec-448f-a91e-e4d12a4b4177
< 1.0.14
MEDIUM 6.1 The MAS Companies For WP Job Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use… wordfence
dc26fef6-58e8-441c-ae72-19a3822903a5
< 3.8
MEDIUM 6.1 The wp-mpdf plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.7.1… wordfence
dc221b37-565d-41e4-874c-06015753045f
< 0.5.7
MEDIUM 6.1 Cross-site scripting vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to inject arbitrary w… wordfence
dc20180b-4665-4ade-b512-b0f0148200e7 MEDIUM 6.1 The SH Email Alert plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mid' parameter in all v… wordfence
dc19228f-c7a2-4600-a7b7-ba813b8035de
< 3.4.5
MEDIUM 6.1 The Musico theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and excluding, 3.4.5 d… wordfence
dc15bc48-31f6-4829-8f9b-cd2d1c7c5280
< 3.3.33
MEDIUM 6.1 The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
dc0b704d-f996-4125-9c27-753497c6e9d4 MEDIUM 6.1 The Passbeemedia Web Push Notification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versi… wordfence
dbe5def5-3413-4697-9f0f-3bd33c5897af
< 4.9.9.7
MEDIUM 6.1 The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
← Prev 798 799 800 801 802 803 804 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top