πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 803 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
dafd1821-1f37-4193-b4bf-19a3d2d15946
< 1.1.5
MEDIUM 6.1 The fossura-tag-miner plugin before 1.1.5 for WordPress has XSS. wordfence
dafc40bf-833a-4d42-b9bc-c7cf2b234ef5
< 6.3
MEDIUM 6.1 The wp-greet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.… wordfence
dafbd32c-ef66-4c1c-aa6b-68443e12eacb MEDIUM 6.1 The AlT Report plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
daf6ae92-dd50-4592-bb61-047a7ecd3646 MEDIUM 6.1 The Exhibit to WP Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
daedec14-6177-43c7-89d4-a39c13d94ca4
< 4.21.1
MEDIUM 6.1 The LMS by LifterLMS plugin for WordPress has a reflected cross-site scripting vulnerability in the in versions up to, a… wordfence
dae7d642-98bd-42c8-a0d1-628402e620f1 MEDIUM 6.1 The Target Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
dadfc9c5-79cb-4e43-bf27-8a7f059190e3
< 2.3.6
MEDIUM 6.1 The animate-it plugin before 2.3.6 for WordPress has XSS. wordfence
dad7ef01-cc14-423d-93a7-11fc0537473b MEDIUM 6.1 The Jigoshop – Store Exporter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
dad7078d-16bf-4ca9-9a59-7b8374a1b49e MEDIUM 6.1 The mgl-instagram-gallery plugin for WordPress has XSS via the single-gallery.php media parameter. wordfence
dad12b10-2e04-4bc2-b5ad-c00cb287e456
< 1.0.1
MEDIUM 6.1 The WDS Multisite Aggregate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the use of add_quer… wordfence
dac94b37-ba4f-43c3-88b3-066401acada2 MEDIUM 6.1 The Goodlayers Hotel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
dac38b2e-4d38-4b16-b6a1-ed3c0561e7c2
< 1.9.30
MEDIUM 6.1 The WPtouch plugin for WordPress is vulnerable to Open Redirect in versions before 1.9.30. This is due to insufficient i… wordfence
dab1dbc7-f188-4c04-9c8b-465ec0a42548 MEDIUM 6.1 The Zuppler Online Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
daac4d63-3789-4262-9b06-aadb4ca1f01e
< 3.4.3
MEDIUM 6.1 The Groundhogg plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.… wordfence
daa4260a-8c50-4fdb-be4f-6a1fb5bcff01
< 3.4.7
MEDIUM 6.1 The WP2LEADS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.4.… wordfence
da9e3db0-9cbf-4b1a-bdaa-d5d86be744af
< 4.4.12
MEDIUM 6.1 The Simple File List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜tab’ and 'subtab'… wordfence
da89e8f9-3843-4d72-92b2-cd2f717510cd
< 2.5.2
MEDIUM 6.1 The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' p… wordfence
da879b1d-c17b-409b-9fd3-87f44ddd14b5 MEDIUM 6.1 The Advance Post Prefix plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in… wordfence
da84aa80-7ef6-4846-870d-07bf88652329
< 6.16.2
MEDIUM 6.1 The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for Wo… wordfence
da81eb8b-4b38-462d-a85b-c0bad39f61a2
< 1.6
MEDIUM 6.1 The BP Email Assign Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parame… wordfence
da81c849-fc85-4794-a79f-fcc3ef6a3bbc MEDIUM 6.1 The WooCommerce EnvioPack WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the dataid parameter foun… wordfence
da7c18b3-d406-4fe6-8c72-fa0cb968c0ac MEDIUM 6.1 The Awesome Logos plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
da5ba18a-97ec-42c5-a7c4-ca38611c1fcd MEDIUM 6.1 The Easy Student Results plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'edit' parameter i… wordfence
da5b700c-ec1f-4803-8165-581382cef482
< 5.3.16
MEDIUM 6.1 The Social Auto Poster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
da4f81c5-c796-4052-ac1a-007a1e8f5a50
< 1.2.1
MEDIUM 6.1 The Form - Contact Form WordPress plugin through 1.2.0 does not sanitize and escape Custom text fields, which could allo… wordfence
← Prev 800 801 802 803 804 805 806 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top