πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 811 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d2e99867-4992-47b5-a642-abd104eee18f
< 1.9.7
MEDIUM 6.1 The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it b… wordfence
d2ccdafb-39f4-4249-95fa-a3d752c435f4
< 3.2.5
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the Better WP Security (better_wp_security) plugin before 3.2.5 f… wordfence
d2c6fefe-f6f3-44ce-906c-abad717840d5 MEDIUM 6.1 The Bounce Handler MailPoet 3 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parame… wordfence
d2aea3e1-60cb-4992-a217-4250bed2641e
< 1.3.1
MEDIUM 6.1 The Ultimate Instagram Feed - WordPress Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜… wordfence
d2aabec9-1968-4c0e-baed-9aa78eb236e8
< 2.0.1
MEDIUM 6.1 The WP Brutal AI plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via admin settings in versions be… wordfence
d2a95c6f-7248-4805-af86-11fd536b5d8d
< 1.0.2
MEDIUM 6.1 The WPZOOM Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via certain input fields in v… wordfence
d29ac638-c067-41a8-8b11-cc3e5b0be514 MEDIUM 6.1 The Fantastic ElasticSearch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
d2989589-0d68-486d-8a3a-d0cff48dfecc MEDIUM 6.1 The Age Verification for your checkout page. Verify your customer's identity plugin for WordPress is vulnerable to Refle… wordfence
d295e2c6-4e0c-4b52-83dc-6363267a0c71 MEDIUM 6.1 The Visitor Maps Extended Referer Field plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions… wordfence
d29581bb-f9f4-473a-b1b4-030cd4f5b8c2 MEDIUM 6.1 The Wibiya Toolbar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
d28e5374-dd34-4745-a20b-059e9846d96d MEDIUM 6.1 The Blog Settings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all v… wordfence
d25f23cc-6012-4607-a643-5350175a439b MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in jwplayer.swf in the smart-flv plugin for WordPress allow remote a… wordfence
d254e43f-8a8b-4309-91f3-c60710c13647
< 1.8.22
MEDIUM 6.1 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
d24c9310-5470-4d08-83b3-c801f4d25d3e
< 1.19.0
MEDIUM 6.1 The Grow Social plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wit… wordfence
d24c65b6-20da-4f17-be9f-b8fbf5e721e3
< 1.2.55
MEDIUM 6.1 The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in … wordfence
d2427236-f8cf-4fbf-8461-77bb75638a0a
< 1.1
MEDIUM 6.1 The Roi Calculator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
d23ac5df-3331-47e0-94b7-53ac8f228935
< 6.1.8
MEDIUM 6.1 The Fancy Product Designer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
d2388b82-3c2a-4b39-88b7-5a8e613ff781
< 14.8.1
MEDIUM 6.1 The Simple Link Directory Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… wordfence
d2246fac-0d95-4ff5-ad1e-aa1fefa03b4d
< 2.4.0
MEDIUM 6.1 The Kubio AI Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramet… wordfence
d224151c-0fe2-4032-a847-39628cc2f520 MEDIUM 6.1 The Seo Monster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3… wordfence
d223de07-6377-491f-8d2c-9c31aa814792
< 32.0.7
MEDIUM 6.1 The PPOM for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via certain query paramete… wordfence
d22134ec-00ca-4672-b9b1-1b1efad13aeb
< 10.6.6
MEDIUM 6.1 The Wp EMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10… wordfence
d216f8ea-2253-475d-9d23-9a83bfa2c21f
< 4.2.12
MEDIUM 6.1 The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has XSS in the Add Product Manually component. wordfence
d20eb274-e578-445f-95f4-5e677d9ad7f3
< 0.9.7.4
MEDIUM 6.1 The W3 Total Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to insufficient input valida… wordfence
d20830a9-f660-4d16-8b11-a03d17d85bba
< 2.9.3
MEDIUM 6.1 The Revolution Video Player With Bottom Playlist WordPress Plugin - YouTube/Vimeo/Self-Hosted Support plugin for WordPre… wordfence
← Prev 808 809 810 811 812 813 814 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top