πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 812 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d204ed58-efb2-4383-aa0f-cbad0bae4d02
< 1.4.2
MEDIUM 6.1 The Bitcoin Lightning Publisher for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t… wordfence
d203f477-ca42-40a2-842e-9af98dd9d410
< 4.0.29
MEDIUM 6.1 The Event Manager, Events Calendar, Booking, Registrations and Tickets – Eventin plugin for WordPress is vulnerable to… wordfence
d1f86c9d-38dc-4d5d-af37-9443348fe1e8
< 1.07
MEDIUM 6.1 The Redirect By Cookie plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
d1ed7ed0-5bcd-42ca-ab56-70ebd3d3c63a
< 1.2.3
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in templates/printAdminUsersList_Footer.tpl.php in the GarageSale plugin before… wordfence
d1e37bca-4fca-4ec4-b48b-b423ec7e129c MEDIUM 6.1 The WordPress Google Map Professional (Map In Your Language) plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
d1e30342-143d-4ea3-9947-b5e5c55725a7
< 3.9.3
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Save Filters functionality in the WP Slimstat plugin before 3.9.3 for Wo… wordfence
d1cb4c3d-f4c0-4464-b14d-ce45151bd661 MEDIUM 6.1 The RSVPMaker Volunteer Roles plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… wordfence
d1c80d7c-0eab-4437-ad03-9789d34638a1
< 1.1.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in wp-newblog.php in WordPress multi-user (MU) 1.0 and earlier allows remote at… wordfence
d1c1847c-8cc9-4080-8da5-7364c4358034 MEDIUM 6.1 The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versi… wordfence
d1bc3fe4-ebca-4379-b920-6602fc06be4d MEDIUM 6.1 The HTML5 Video Player with Playlist & Multiple Skins plugin for WordPress is vulnerable to Reflected Cross-Site Scripti… wordfence
d1ae714b-4811-4ffa-ba8d-82ad6b948704 MEDIUM 6.1 The Easy School Registration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
d1abc6ef-2488-4a99-886c-3194e47b22d0 MEDIUM 6.1 The WooCommerce Shop Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions u… wordfence
d1a7e39a-5fd1-4bb3-9cd9-4bded794f8f0
< 2.3.1
MEDIUM 6.1 The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-syste… wordfence
d1925082-eeee-4472-9721-c6205782d567 MEDIUM 6.1 The Migrate Users WordPress plugin through 1.0.1 does not sanitise or escape its Delimiter option before outputting in a… wordfence
d178b2c9-a157-4e53-a7d7-940370cb3b57 MEDIUM 6.1 The Header Image Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
d16f7c33-0e60-43bb-b200-883cced640f3
< 3.11.1
MEDIUM 6.1 The YITH WooCommerce Ajax Product Filter plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, a… wordfence
d167a483-7190-4285-a055-2280cc36f9c6 MEDIUM 6.1 The BP Member Type Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
d1418658-e068-4f49-a959-3bc8283c239a
< 3.3.74
MEDIUM 6.1 The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Open Redirect in all versions up … wordfence
d1408c27-2328-4228-bba4-e28b263851c6 MEDIUM 6.1 The Frizzly plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1.0… wordfence
d13d072e-9c9c-4a32-b9f4-7d15dc704b50
< 3.2.9
MEDIUM 6.1 The Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Reflected … wordfence
d13ca79f-50fa-4395-8de1-b58a9459a34c MEDIUM 6.1 The VKontakte Cross-Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
d122321a-d714-4283-89b8-dc7dbfa96b20 MEDIUM 6.1 The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to… wordfence
d11d5dbc-7329-40ed-8e84-d57fa59460a4
< 6.15
MEDIUM 6.1 The SKT Templates – Elementor & Gutenberg templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripti… wordfence
d11c84ea-e52b-4396-a508-9d415040b76e
< 3.30.3
MEDIUM 6.1 The Leyka plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several $_GET parameters in versions … wordfence
d118beb2-bcb1-4d35-b25e-172fa4b6d916
< 4.0.6
MEDIUM 6.1 The WP-FB-AutoConnect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'jfb_email_to', 'jfb_str… wordfence
← Prev 809 810 811 812 813 814 815 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top