ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 813 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d0f35a20-ffcf-4413-b1ea-748cd6aa6f20 MEDIUM 6.1 The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message … wordfence
d0ec4f27-2057-468e-bfcd-818c50952cac
< 1.3.1
MEDIUM 6.1 The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which inter… wordfence
d0e82bef-3857-4b13-a124-70aeaf90e8ce MEDIUM 6.1 The WP-jScrollPane plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
d0c74637-97b6-44d8-89c7-4a662fc537c6 MEDIUM 6.1 The Monitor.chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
d0b369b4-b107-4207-8d5a-4551a2adf437 MEDIUM 6.1 The Access Category Password plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
d0a38293-3730-44ae-90de-bc94a9e850b1 MEDIUM 6.1 The QR Code for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
d09b638f-4c30-41cc-84fd-ae0816e2c29e MEDIUM 6.1 The Tax Report for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
d08db182-bfbf-42bd-8070-cbd80b3b5759 MEDIUM 6.1 The TubePress.NET plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
d089bfee-3d23-4d35-83e0-7575702a21b4 MEDIUM 6.1 The Better Customer List for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versio… wordfence
d083cf7c-f116-40aa-bffb-91e43ba52490
< 4.0.16
MEDIUM 6.1 The what3words Address Field plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
d06a8ec6-19c0-4c76-8954-2395429bd38b MEDIUM 6.1 The Cookies Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
d062bc7b-0cb0-46bd-b203-90cc9a44a403 MEDIUM 6.1 The Smart External Link Click Monitor [Link Log] plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
d05de50e-1d3b-4e41-bfec-079b5cd82784 MEDIUM 6.1 The SH Slideshow plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
d0598341-0088-42bf-9a34-794c941a848d MEDIUM 6.1 The Vikinghammer Tweet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
d02fc744-35e5-44eb-8790-66997e95d017
< 2.6
MEDIUM 6.1 The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request. wordfence
d021636e-2d23-4fb3-baf7-0f40d4ade3db
< 2.8.5
MEDIUM 6.1 The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info … wordfence
d0206a57-4f1e-4cd2-a854-d435d769f391 MEDIUM 6.1 The Product Puller plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
d014f512-9030-49ce-945d-4900594fb373
< 2.6.1.2
MEDIUM 6.1 The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in … wordfence
d0033a19-47ac-4ffc-93a4-2ea693e93397
< 1.5.69
MEDIUM 6.1 The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'album_gallery_i… wordfence
CVE-2026-2506 MEDIUM 6.1 The EM Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… nvd
CVE-2026-2502 MEDIUM 6.1 The xmlrpc attacks blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… nvd
CVE-2026-1706
< 4.7.5
MEDIUM 6.1 The All-in-One Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'vi' parameter… nvd
CVE-2026-1666
< 3.3.47
MEDIUM 6.1 The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' paramete… nvd
CVE-2026-1296 MEDIUM 6.1 The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, … nvd
CVE-2026-0561 MEDIUM 6.1 The Shield Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in … nvd
← Prev 810 811 812 813 814 815 816 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top