🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 814 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2025-11706
< 3.0.3
MEDIUM 6.1 The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the dbstatus parameter … nvd
cffe745d-2fe2-4959-9641-9a0ae33bff4c
< 4.2.1
MEDIUM 6.1 The Simple Payment Donations plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
cff6b26e-bafa-4b85-b7f1-eea9bb4b6476
< 3.3
MEDIUM 6.1 The Advanced Sermons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sermon_dates' paramet… wordfence
cff04656-5930-4324-9ddf-43a2166cdf04
< 4.6.20
MEDIUM 6.1 The Molongui plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in versions u… wordfence
cfecc35a-30e2-4474-b727-ec2fcbf07e0c MEDIUM 6.1 The Custom CSS Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
cfec4c31-ba09-4832-a095-4ca5f5192674 MEDIUM 6.1 The ENL Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
cfe4d99c-9cbd-4255-8f90-f904313d46b4
< 3.4.4
MEDIUM 6.1 The Dashboard Widgets Suite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter… wordfence
cfd3f0e3-e73e-4ec2-ac67-da1cc15aa217
< 3.5.7
MEDIUM 6.1 The Simple Membership plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.5.6… wordfence
cfcc1a4d-c6c7-4ca8-afe5-79298e7ad3d7
< 1.3.3
MEDIUM 6.1 The Balkon theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3.2 d… wordfence
cfc09dee-9af6-49ff-bfe2-abcc616940d7
< 4.3
MEDIUM 6.1 The MW Font Changer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'size' parameter in ver… wordfence
cfbd41fa-15f0-473a-be5a-862e8a14b287
< 3.2.3
MEDIUM 6.1 The Restrict Content plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via POST data from the rcp_aja… wordfence
cfb6e263-efcc-4ecb-8c9a-91f73f82b55a MEDIUM 6.1 The Scroll Styler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
cfb52a38-2894-4b43-b936-a11fa6257741 MEDIUM 6.1 The AffiliateImporterEb plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'module' parameter … wordfence
cf8817fd-b49a-4fb3-9c91-09e952ff0953 MEDIUM 6.1 The WP Click Info plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
cf67d95a-7819-49b7-8a2a-ea945a0167b1 MEDIUM 6.1 The My Marginalia plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
cf6182b6-c291-4020-a016-5c6b96039549 MEDIUM 6.1 The PRIMER by chloédigital plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
cf5f0f9f-b0b1-4ac8-a8c2-e349dfb9e6c3 MEDIUM 6.1 The WP Finance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
cf4e9b41-20e8-4dba-a51c-6e8f09232ffb
< 3.6.22
MEDIUM 6.1 The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parame… wordfence
cf4d42a2-746b-4c23-b0fe-b66eafb76303
< 1.2.3
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allow remote at… wordfence
cf458f57-2c8b-44d1-8e36-bbfc1a66c2e2 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in shortcode-generator/preview-shortcode-external.php in the OMFG Mobile Pro pl… wordfence
cf3f82dc-3820-4c9d-adbb-ca0375078876
< 2.3.2
MEDIUM 6.1 The IDPay for Contact Form 7 WordPress plugin through 2.1.2 does not sanitise and escape the idpay_error parameter befor… wordfence
cf3a16b6-7256-4fad-b3f2-d1d9d833f45e
< 2.2.1
MEDIUM 6.1 TheConvertKit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in versions … wordfence
cf2f2474-50d6-46da-a97c-731edb514ae5
< 1.1.1
MEDIUM 6.1 The Manage Calameo Publications by Athlon for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attac… wordfence
cf2d14ff-d02a-4bed-9604-ff2489d4bef9 MEDIUM 6.1 The Corona theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and output e… wordfence
cf21c4a8-2e26-4235-8c9b-cda31a687a87 MEDIUM 6.1 The Musicbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'webdesignby-musicbox-filter' … wordfence
← Prev 811 812 813 814 815 816 817 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top