🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 802 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
dbdb8fad-93de-40c5-8e1e-6e8885bc8025 MEDIUM 6.1 The MDC YouTube Downloader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
dbc5edda-c503-4a0c-be9e-6ce17eee2c51
< 1.9.19
MEDIUM 6.1 The icegram plugin before 1.9.19 for WordPress has XSS in 'message' parameter. wordfence
dbc1d257-bc56-4e8f-bdb4-b2a323026625
< 7.0.07
MEDIUM 6.1 Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote attackers to inject arb… wordfence
dbbd9eda-756b-4fa7-b7b6-d91181cc80d6
< 1.4.22
MEDIUM 6.1 The plugin BuddyForms Members is vulnerable to Cross-Site Scripting via various parameters in versions up to, and includ… wordfence
dba7f15a-29f8-4c7b-b506-7e82c563c6a9
< 1.2
MEDIUM 6.1 The MF Gig Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' GET parameter in v… wordfence
dba61faf-b7fa-4910-9101-8f2a3dac8dc9 MEDIUM 6.1 The zeList plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘zmode’ parameter in version… wordfence
dba01dc2-c73b-461a-bcbd-86daa0bf0ad0
< 2.9.11
MEDIUM 6.1 The Ninja Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2… wordfence
db959eaf-300c-4ecd-ac15-216a17ec5a50
< 1.2.9
MEDIUM 6.1 The 10Web Social Post Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
db95415a-5354-498b-8368-58c47d9948de
< 5.1
MEDIUM 6.1 The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ par… wordfence
db8d6f1d-1166-4508-b3c7-be80c723bd5d MEDIUM 6.1 The Tab My Content plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
db8c4bd1-8886-40a4-98e2-e42fc1b81fc9
< 6.5.1
MEDIUM 6.1 The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'editaff' paramet… wordfence
db75aa9d-c21c-4cfd-be5a-11dd00a89845
< 6.1.0
MEDIUM 6.1 The SMSify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.0.4 … wordfence
db759c60-9ce9-407d-8d1f-cbbfd09759d5
< 1.4.3
MEDIUM 6.1 Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in v… wordfence
db73eab3-c974-4098-b83c-4a5baf9b1ea8
< 1.0.2
MEDIUM 6.1 The Tida URL Screenshot plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
db6ccadb-5e90-4234-88cc-28241846acea MEDIUM 6.1 The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wp… wordfence
db5e26cf-e6c7-4b79-807a-643a1effd2a0
< 5.8.11
MEDIUM 6.1 The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘searchll’ parameter i… wordfence
db5764f7-3e5e-4a0f-8280-c851ccb7dbc3
< 1.1.6
MEDIUM 6.1 The Ready! Google Maps plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.… wordfence
db5247ad-dbbf-4d8e-92f5-3a673b97d080
< 1.22
MEDIUM 6.1 The Video Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in ver… wordfence
db491dff-8301-4df8-a7b7-5024b145d038 MEDIUM 6.1 The MACME plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2 due… wordfence
db48a271-e649-4dbe-901b-aa55eba9123b
< 5.1.4
MEDIUM 6.1 The Photo Gallery by Ays plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ays_gpg_setting… wordfence
db3b206d-16c5-48fb-800d-d017a0c76630
< 2.1.7
MEDIUM 6.1 The Ultimate Member plugin for WordPress is vulnerable to open redirects in versions up to, and including, 2.1.6 This is… wordfence
db2d5cc4-70e9-4512-8004-b6735c2c3ee1
< 1.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Responsive Logo Slideshow plugin for WordPress allows remote attackers t… wordfence
db2a0b6f-5629-4ebe-8431-ebb3bc583e31
< 6.0.0
MEDIUM 6.1 The WordPress Popular Posts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_q… wordfence
db2915ca-610a-42a9-a4f8-d15729091cd6 MEDIUM 6.1 The More From Google WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_S… wordfence
db089aa4-63b8-4122-8075-c81f3fcc57bd
< 2.0
MEDIUM 6.1 The CSS3 Vertical Web Pricing Tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all version… wordfence
← Prev 799 800 801 802 803 804 805 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top