🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 808 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d5ef3350-3eec-48b7-9241-5d2ce25555f0
< 7.1.18
MEDIUM 6.1 The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or esca… wordfence
d5ed7f73-34aa-45ac-a4c8-81bb78d9e63f MEDIUM 6.1 The Board Document Manager from CHUHPL plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versi… wordfence
d5e70f6f-fc83-4c89-a1d5-35f188e0fd90
< 3.20.0
MEDIUM 6.1 The FG PrestaShop to WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ajax_impor… wordfence
d5e431f2-30f6-4c4d-8e15-20b1bf1888c6 MEDIUM 6.1 The OK Poster Group plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
d5e0d63c-64a9-4861-9c70-c0f4d82a042e
< 9.3
MEDIUM 6.1 The LMS theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 9.2 du… wordfence
d5d3e333-4dcd-414b-85a6-8d9fbef357bd
< 3.0.5
MEDIUM 6.1 The SEO Friendly Images plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in vers… wordfence
d5cab96c-f6ab-4ee6-8453-22e8a39cc82f
< 1.0.2
MEDIUM 6.1 The Mark User as Spammer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions u… wordfence
d5c23952-3732-4316-aa43-ddab88a6ba79
< 0.2
MEDIUM 6.1 The Rating by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 0.2 due… wordfence
d5bf4972-424a-4470-a0bc-7dcc95378e0e
< 5.9.2
MEDIUM 6.1 The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ paramet… wordfence
d59ea96f-ad02-4189-8155-7de7de5556ba
< 1.22
MEDIUM 6.1 The Additional Order Filters for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… wordfence
d5947859-df78-475b-89b4-ad2441d9cf63
< 3.0.4
MEDIUM 6.1 The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before ou… wordfence
d586f258-ddd4-48a1-9c7a-2d1b343b0d23
< 2.6.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the post highlights plugin versions 2.0 through 2.6 for WordPress allows rem… wordfence
d5848d3a-d6a8-4e56-9012-9d600a3cf7fa
< 1.2.5
MEDIUM 6.1 The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page befo… wordfence
d570009f-0011-485a-bd14-f511cb2b60d7
< 1.3.1.1
MEDIUM 6.1 The indieweb-post-kinds plugin before 1.3.1.1 for WordPress has XSS via the genericons/example.html anchor identifier. wordfence
d557ccb4-99c3-4286-91cd-87576a95f179 MEDIUM 6.1 The Repagent theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and output… wordfence
d55737a5-8aa5-4c26-bbb5-bbc5ea8be8d1
< 3.1.2
MEDIUM 6.1 The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress i… wordfence
d55033fb-17a6-4b8d-87f4-1c102ef7dbcd
< 1.4.0
MEDIUM 6.1 The limb-gallery (aka Limb Gallery) plugin < 1.4.0 for WordPress has XSS via the wp-admin/admin-ajax.php?action=grsGalle… wordfence
d541f86a-744e-498e-bfab-b1a917c6ac49 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Easy Career Openings plugin 0.4 and earlier for WordPress allows remote … wordfence
d53c16c6-9a67-4bfa-a993-4b391d24be23 MEDIUM 6.1 The UXsniff plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.8… wordfence
d539a066-6b59-4235-868e-f3085436e9f4 MEDIUM 6.1 The Gantry 4 Framework plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'override_id' parame… wordfence
d5396344-abb6-4ab5-9974-8ccbe8ca5842 MEDIUM 6.1 The Super Edit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.… wordfence
d536d3a8-9ac5-4ea9-8c65-16ad8b3a7106
< 2.8.1
MEDIUM 6.1 The Happy Elementor Addons Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown param… wordfence
d53069a3-5b8e-4ee1-b4da-97ff8f58ab03
< 1.99.20
MEDIUM 6.1 The Code Styling Localization plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includin… wordfence
d52f6779-efb3-42ed-95b0-c950b51c96f3 MEDIUM 6.1 The Image&Video FullScreen Background plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions u… wordfence
d52cdc45-efea-46b5-9004-f3169e807747
< 2.9.5
MEDIUM 6.1 A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remot… wordfence
← Prev 805 806 807 808 809 810 811 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top