🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 809 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d524a2c1-43df-4059-b1ec-b0738026158e
< 2.8.2
MEDIUM 6.1 The "Travel Booking WordPress Theme" theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘adul… wordfence
d5111215-7ce9-46e3-b247-c3f0f28ec094
< 6.1.4
MEDIUM 6.1 The AI Content Writer, RSS Feed to Post, Autoblogging SEO Help plugin for WordPress is vulnerable to Reflected Cross-Sit… wordfence
d50d8d51-3bb4-4556-95e3-06812a31d0d6
< 1.0.27
MEDIUM 6.1 The Image Optimizer WD plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'iowd_tabs_active' p… wordfence
d4efe60a-d8e3-4e51-95b2-246e30e90e89
< 2.8.7
MEDIUM 6.1 The uncode-core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all ver… wordfence
d4e1ddaa-d05a-4261-b55d-54d7650c12b8 MEDIUM 6.1 The SMS for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in … wordfence
d4cb4dea-afaa-4ab5-a48a-f1bee6d4665b
< 2.3.5
MEDIUM 6.1 The Striking theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.3.4… wordfence
d4c6d0ef-fe2c-4449-9e9c-135529a99575
< 3.2
MEDIUM 6.1 The Soundy Background Music plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'war_soundy_aud… wordfence
d4c2e35a-f271-45b0-a3b6-9a1dbbcaf72f MEDIUM 6.1 The WP eCommerce Quickpay plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
d4bf80cd-8956-4143-afcb-995013554d56
< 1.4.2
MEDIUM 6.1 The my-wish-list plugin before 1.4.2 for WordPress has multiple XSS issues. wordfence
d4beb0b7-e287-43bd-b8d1-3aa65e268ead
< 3.0.3
MEDIUM 6.1 The Calendarista Basic Edition plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includi… wordfence
d4ba4365-449e-4271-b46e-7f149efc752c
< 3.8.16
MEDIUM 6.1 The Video Conferencing with Zoom plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘host_id… wordfence
d49a2180-cf3f-4ef9-805f-e7592b793a2c MEDIUM 6.1 The WP Ultimate Email Marketer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'listname' & '… wordfence
d47f7f24-2938-4af6-93b8-1aefb41bbae2
< 0.9.3
MEDIUM 6.1 The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
d46f8e8a-80cb-4407-ac07-f4c93be691b6
< 4.6.0.3
MEDIUM 6.1 XSS was discovered in the RegistrationMagic plugin 4.6.0.1 for WordPress via the rm_form_id, rm_tr, or form_name paramet… wordfence
d46edcfe-ab6b-4966-9d85-40a2e2ee3d44
< 1.3.2.3
MEDIUM 6.1 The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dn' parameter on the 'cha… wordfence
d4631eff-1faa-4cce-859f-1c2132376d93
< 2.6.6
MEDIUM 6.1 The Auto SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.… wordfence
d460cc34-c8b0-453b-9b6b-3bd53137625a
< 1.6.02
MEDIUM 6.1 The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in ver… wordfence
d4325e51-5d57-4763-a6c4-29c67330bdbd
< 0.4.2.8
MEDIUM 6.1 The FoxyPress plugin for WordPress is vulnerable to Open Redirects in versions up to, and including, 0.4.2.7. This is d… wordfence
d41fb15c-9e0b-46d2-b60b-4213facc02a7
< 3.9.2
MEDIUM 6.1 The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & El… wordfence
d419fceb-731b-4b45-b995-46e7e0fedb38 MEDIUM 6.1 The Movylo Marketing Automation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up … wordfence
d4170426-b418-48ec-8233-1ca1aca60473
< 1.4.2.3
MEDIUM 6.1 The DW Question & Answer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dwqa_anonymous_nam… wordfence
d41355ed-77d0-48b3-bbb3-4cc3b4df4b2a
< 6.1.0.0
MEDIUM 6.1 The Digirisk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'current_group_id' parameter i… wordfence
d4093f00-838b-49d1-930c-c7ee2238046f
< 1.6.3
MEDIUM 6.1 The Photo Gallery by 10Web WordPress plugin before 1.6.3 does not properly sanitize the $_GET['image_url'] variable, whi… wordfence
d4070a24-04fa-44e8-8ec2-bc84ba53b90d
< 1.5.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Web Dorado Spider Video Player (aka WordPress Video Player) plugin befor… wordfence
d3fb6a84-2339-4d5c-a88a-f8e08a940840 MEDIUM 6.1 The Responsive Zoom In/Out Slider WordPress Plugin plugin for WordPress is vulnerable to Cross-Site Scripting via the 'a… wordfence
← Prev 806 807 808 809 810 811 812 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top