πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 805 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d918cfa5-8bae-45a0-a888-06f4cdb2ef33
< 3.4.8.6
MEDIUM 6.1 The weblibrarian plugin before 3.4.8.6 for WordPress has XSS via front-end short codes. wordfence
d911be19-6b8c-4e38-b955-7f8826aeed8a
< 2.0.12
MEDIUM 6.1 The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Script… wordfence
d9051cdb-b894-49a3-84a6-7470f8323706 MEDIUM 6.1 The Login-box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0… wordfence
d8f7d1c3-50eb-44ef-a832-a0230ff1406f
< 4.5
MEDIUM 6.1 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Reflected Cross-Si… wordfence
d8f6d1cb-330b-4405-9249-4dd1c0e98922
< 2.6.1
MEDIUM 6.1 The google-document-embedder plugin before 2.6.1 for WordPress has XSS. wordfence
d8e95efa-1c34-4267-b93f-bb850f0a6e85 MEDIUM 6.1 The MFPlugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.… wordfence
d8e5fccd-3b6c-4142-97ef-2166b5a4708f MEDIUM 6.1 The ShowTime Slideshow plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
d8d4bc5a-7f76-4103-92e7-d7fe265fc255 MEDIUM 6.1 The Len Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.… wordfence
d8d44f9b-0eee-49ee-b640-40f3bd377be0
< 1.5.3
MEDIUM 6.1 The WooCommerce - Product Importer WordPress plugin through 1.5.2 does not sanitise and escape the imported data before … wordfence
d8c89641-805f-4f23-9eae-01e05fde19d0 MEDIUM 6.1 The .htaccess Redirect WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the link parameter found in … wordfence
d8c466cf-44d1-480f-8ef2-2b78040618ca MEDIUM 6.1 The Omnify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0.3 … wordfence
d8bf1d64-8012-4588-9897-aa8bb0cacfb6
< 3.4.0
MEDIUM 6.1 The GiveWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.3.1 … wordfence
d8ba1a2f-d4f9-4cfe-9a42-ec2e116aed1b
< 4.1.8
MEDIUM 6.1 The Rezgo Online Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters suc… wordfence
d8a56a1c-6af0-47e6-906c-bb3eb1440eb9
< 2.3.10
MEDIUM 6.1 The My Calendar plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 2.3.10 due to insufficient… wordfence
d891caca-40be-4905-b5c3-bc3f2ddcd3cd
< 0.7
MEDIUM 6.1 The AZAN Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0… wordfence
d890e7a5-ea9f-40e5-9549-a6f26421b043 MEDIUM 6.1 The Easy Load More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg … wordfence
d88a7c35-fe98-48eb-960b-0e4f8fcab4cb
< 1.3.10
MEDIUM 6.1 The Easy Digital Downloads (EDD) Reviews extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.… wordfence
d875969e-3749-4f0b-a807-36609bfca4d3
< .49
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the security log in the BulletProof Security plugin before .49 fo… wordfence
d857324c-94c9-471a-9da8-0b8c9bb50262
< 3.1.2
MEDIUM 6.1 The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜p… wordfence
d8461a10-44e1-437a-ad6c-7107aeb66124
< 1.0.46
MEDIUM 6.1 The WordPress Affiliates Plugin β€” SliceWP Affiliates for WordPress is vulnerable to Reflected Cross-Site Scripting via… wordfence
d837fb74-d938-466d-8fe8-1ca345349338 MEDIUM 6.1 The Samex - Clean, Minimal Shop WooCommerce WordPress theme for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
d82d1dd2-b5b5-490a-92e5-1a4d4ab0085d
< 2.1.1
MEDIUM 6.1 The Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '… wordfence
d80a6f8b-8528-48a5-a4f0-01b0b55de95a MEDIUM 6.1 The RVCFDI para Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
d8081c02-9280-4cb7-9b6c-e04d34f2439c MEDIUM 6.1 The WordPress Photo Gallery – Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ve… wordfence
d800a4e5-0af4-47b5-bdeb-126b21ad0ff1 MEDIUM 6.1 The Fyrebox Quizzes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
← Prev 802 803 804 805 806 807 808 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top