🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 845 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b0297b3a-a180-428a-9716-6ecfa5a4de94
< 1.7.2
MEDIUM 6.1 The magic-fields plugin before 1.7.2 for WordPress has XSS via the custom-write-panel-id parameter. wordfence
b02613dc-8c31-4c86-b800-eb1039381e1f
< 1.4.8
MEDIUM 6.1 The Invite Anyone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
b0086de8-448f-452f-89d1-84b77b2e25a8
< 4.4.2
MEDIUM 6.1 The Simple Membership plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.4.1. T… wordfence
b004955a-7580-4dc8-beee-e55785026fed
< 1.5.35
MEDIUM 6.1 Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi… wordfence
b00290ee-ad63-4544-818a-c0d7471e60fa
< 3.5.5
MEDIUM 6.1 The Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘settings’ hash parameter… wordfence
afff886c-92e6-41fc-9a88-befc158ad403 MEDIUM 6.1 The CodeBard's Patron Button and Widgets for Patreon plugin for WordPress is vulnerable to Reflected Cross-Site Scr… wordfence
afff64c5-ed38-4aef-9ed6-4a44589b025c
< 5.2.4
MEDIUM 6.1 Core\Admin\PFTemplater.php in the PressForward plugin 5.2.3 and earlier for WordPress has XSS in the PATH_INFO to wp-adm… wordfence
affc9dff-75a1-4cb3-8465-55254db6441b MEDIUM 6.1 The Q2W3 Post Order plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all… wordfence
aff495c6-b4b6-4389-8acf-f59676f12e1f MEDIUM 6.1 The SEO Tools plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'src' parameter in all versio… wordfence
afd58164-8d33-4f93-a904-443b1df8b66b
< 1.3
MEDIUM 6.1 The Rimons Twitter Widget plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1… wordfence
afc85535-962d-479d-8580-9d02f7412930
< 4.0.1
MEDIUM 6.1 The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Refle… wordfence
afc82959-35a3-41a3-ae72-f9184b7c331d MEDIUM 6.1 The User List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5… wordfence
afc20673-5665-4058-9d77-ebe9c03df46f
< 8.9
MEDIUM 6.1 The MagOne theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 8.8 due… wordfence
afbb1f20-188b-4874-98dd-ab1fa43bb276
< 3.1.10
MEDIUM 6.1 The VForm plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.1.9 d… wordfence
afb58149-cff0-4911-8322-c608fc00adf4
< 14.2.1
MEDIUM 6.1 The GEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
afb3e2f8-ba44-48fc-9882-d9bcd39676ee MEDIUM 6.1 The upscale theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and output … wordfence
afb032da-11cc-4272-be68-60b6ca6e6ca3
< 2.5.0
MEDIUM 6.1 The Image Slider by Ays- Responsive Slider and Carousel box plugin for WordPress is vulnerable to Reflected Cross-Site S… wordfence
af99651a-2975-4985-a7de-bdd8ab0d92d0 MEDIUM 6.1 The Rich Text Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
af838653-d575-48fc-bded-f0068a6c6ebf
< 4.0.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Tweet Blender plugin before 4.0.2 for WordPress allows remote attackers … wordfence
af7f5e86-3e88-4fb1-942d-f755ae60f088
< 2.7.2.5
MEDIUM 6.1 The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… wordfence
af71ca13-781d-49ca-948c-03d52d91d11b
< 0.8.1
MEDIUM 6.1 The Debug Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg witho… wordfence
af59102e-f029-4c7d-95ee-16b9dcef4827 MEDIUM 6.1 The Broadscope theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and outp… wordfence
af568eea-59ce-467e-ba03-625d04d3db6e
< 1.25.1
MEDIUM 6.1 The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t… wordfence
af48906b-f7b2-45ec-b0c1-1ac521106759
< 2.1.6
MEDIUM 6.1 The WP Matterport Shortcode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the use of PHP_SELF… wordfence
af4058cd-79bc-433c-96e1-fb0aad12969c
< 0.9.1
MEDIUM 6.1 The WP OER plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to… wordfence
← Prev 842 843 844 845 846 847 848 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top