ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 807 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d6e1cc0d-2c5f-4e34-bd19-d7c90cd4dff6
< 2.16
MEDIUM 6.1 The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use … wordfence
d6c906b3-8819-409c-946a-eeb9d938142d MEDIUM 6.1 The VRView plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an outdated VRView library in versio… wordfence
d6c85f2b-965d-477f-9d9a-4a3f315c4904
< 4.24.2
MEDIUM 6.1 The MyParcel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg withou… wordfence
d6ae4764-8792-4457-bc75-f26f9d0284b6
< 1.11.3
MEDIUM 6.1 The URL Shortify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
d6a44d36-43e6-4785-b2bc-0b4b98d847e7
< 3.4.5
MEDIUM 6.1 The Terms Descriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the term_search name par… wordfence
d6a1a2c2-e754-43e5-84b5-579a805c8d71 MEDIUM 6.1 The Bookshelf plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the swfupload.swf file in version… wordfence
d6951a50-954b-4c2b-8499-7623027406c8 MEDIUM 6.1 The Weekly Class Schedule plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
d694491c-c0f5-4418-805a-db792ea4f712
< 3.4.15
MEDIUM 6.1 Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in v… wordfence
d68bbf0d-72e9-4295-a1e1-4abeb36cae1b
< 2.10.3
MEDIUM 6.1 The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is … wordfence
d68841f1-f3f2-45e7-8a4f-d2d65624b617
< 4.8
MEDIUM 6.1 The ND Learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl settin… wordfence
d685c80a-3aad-4778-9aad-de41af33acbf MEDIUM 6.1 The Olivia theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.9.5 d… wordfence
d6847492-6204-40ae-b971-8eeb1a10ce23 MEDIUM 6.1 The Slider for Writers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
d681fcaf-c7b3-496f-b0d8-a8ed48901cec MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the Welcart e-Commerce plugin 1.3.12 for WordPress allow remote a… wordfence
d672a729-d1fc-4ec1-9c0f-c51610fb5ab5
< 6.3.2
MEDIUM 6.1 The Bitcoin and Altcoin Wallets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up … wordfence
d666d0fc-0362-4289-81c4-67f96e729877
< 2.8.1
MEDIUM 6.1 The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to Reflected Cross-Site Scri… wordfence
d641bdd9-b8f9-4811-ae64-adbd694b4a4f MEDIUM 6.1 The Affiliate Tools Việt Nam plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
d63543f9-4865-444f-9a32-3b23e92b0bd4
< 2.1.0
MEDIUM 6.1 The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the… wordfence
d634ba5c-842c-44d0-b919-01c297a779f2
< 1.0.2
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in (1) templates/admanagement/admanagement.php and (2) templates/ads… wordfence
d6221374-3c0d-4d37-8a27-130c504ea70d
< 1.8
MEDIUM 6.1 The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS. wordfence
d611fb0a-f957-4ff7-a402-e0cf0e2c12b6
< 1.1.5.5
MEDIUM 6.1 The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1.5 … wordfence
d60f69f1-eaea-49cb-bbe3-281ec4f872f1
< 1.0.1
MEDIUM 6.1 The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi… wordfence
d607e7c0-7812-4c77-a763-6095677b3525
< 3.3.4
MEDIUM 6.1 The DWT - Directory & Listing WordPress Theme is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
d60261eb-c8b1-4278-aeb8-4ea1abaeed25 MEDIUM 6.1 The RSS News Scroller plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
d5f36574-b4d0-4b67-baea-f5ef5e6618d1
< 2.3.2
MEDIUM 6.1 The Ad Buttons plugin for WordPress is vulnerable to Cross-Site Scripting via Cross-Site Request Forgery via the ‘ab_y… wordfence
d5f0587e-1f84-472c-8fb7-13ddda63e2ec MEDIUM 6.1 The Nouri.sh Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF… wordfence
← Prev 804 805 806 807 808 809 810 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top