ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 817 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cd4a087a-f7cf-451c-85d5-c37a6015b9e1 MEDIUM 6.1 The Contact Form Master – by Edmon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'formI… wordfence
cd4336a9-35db-4994-9e2a-5ed9b51a74ae
< 2.8.4
MEDIUM 6.1 The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests. wordfence
cd41bdb3-67d4-481c-a8b1-feb76df37745 MEDIUM 6.1 The FooGallery Captions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
cd28e5cc-94a2-4a0f-a795-7c2ddb01c35a MEDIUM 6.1 The link-list-manager WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category parameter found … wordfence
cd25daac-23a2-4375-9dc2-8e9f20a564c8
< 1.5.69
MEDIUM 6.1 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected … wordfence
cd11abe3-8307-492b-beef-242fb21a4206
< 2.1.3
MEDIUM 6.1 wordfence
ccfdb5f5-8417-44a3-a27c-157a9619c68b
< 3.18.3
MEDIUM 6.1 The WPPizza plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the use of PHP_SELF in versions up … wordfence
ccf80f2d-3d2d-4fe6-a4c4-5a850cf5bdc8
< 2.3.1
MEDIUM 6.1 The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-syste… wordfence
ccf2198d-b8a4-4838-aefc-5fe9d4e5a061 MEDIUM 6.1 The WP-BusinessDirectory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
cce4a7cc-d93c-4d0e-ba63-b73bee0ea181
< 1.41
MEDIUM 6.1 The Find Slow Functions & Actions & Filters & Hooks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
cce0fd52-b4a3-4608-81ca-f50c859ae6a5
< 2.3.0
MEDIUM 6.1 The WP Media Category Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… wordfence
ccd2ef23-23b7-4a32-aeda-41ea9439f166
< 16.24.48
MEDIUM 6.1 The WP-Recall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date-start' and 'end-start' … wordfence
cccdc9ea-7511-4588-9459-61c38000724d
< 3.1.0
MEDIUM 6.1 Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary … wordfence
ccc7fd8b-ac7d-4b40-816a-a5a1565c422a
< 14.11
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the WP Symposium plugin before 14.11 for WordPress allow remote a… wordfence
ccc2502c-9d26-4041-a020-1db35f144ddf
< 1.12.0
MEDIUM 6.1 The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and excluding, 1… wordfence
cca9f71c-42e6-416f-94f2-cb79bbdfc69a
< 4.7
MEDIUM 6.1 The turboSMTP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all v… wordfence
cca9a0f3-7377-4411-a2e4-55574da614c0 MEDIUM 6.1 The add custom google tag manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
cc98fca3-a68a-437e-bb16-94182f111b8d MEDIUM 6.1 The SendSMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.9… wordfence
cc940d0c-446a-417b-95ac-b5f8a0586906
< 1.7.8.9
MEDIUM 6.1 The Zoho CRM Lead Magnet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
cc8aa5c9-8ffc-4dc6-8b61-8c05aded7749 MEDIUM 6.1 The Robokassa payment gateway for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in al… wordfence
cc5a6724-e860-410e-8a3d-c26d9bc7e842
< 1.3.1
MEDIUM 6.1 The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab paramete… wordfence
cc35af61-363d-463d-844a-8a0b8c37aa27 MEDIUM 6.1 The Style Admin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
cc358df9-7930-44da-8b33-d39db8a87b20
< 2.0.3
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin befor… wordfence
cc2ee5bb-eeb8-4134-8f3f-b411e56457f0
< 9.3.4
MEDIUM 6.1 The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' p… wordfence
cc1e9778-2860-4e3c-a2e4-28f10d585fed
< 1.0.9
MEDIUM 6.1 Multiple CRM Perks plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'vx_debug' parameter i… wordfence
← Prev 814 815 816 817 818 819 820 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top