🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 846 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
af3ee18f-187f-4205-956b-74dacfd1ea3d MEDIUM 6.1 The Easy custom css by webriti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
af0eae51-fb94-4e2e-a9a6-8ba323bb3314
< 1.7
MEDIUM 6.1 The nd-travel plugin before 1.7 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. wordfence
af0cc02a-b6dd-4058-b686-9c9a3a4a5962
< 2.1.4
MEDIUM 6.1 The استخراج محصولات ووکامرس برای آیسی plugin for WordPress is vulnerable to Reflected Cross… wordfence
aef56a34-b98e-4759-bd3f-37fb6f8b18e9 MEDIUM 6.1 The WordPress Call me Now plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
aee79aa4-cb40-4a9c-a5f5-c22c5be509c0 MEDIUM 6.1 The dForms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0 du… wordfence
aed02958-9397-4116-a46a-babc43997afd
< 14.1
MEDIUM 6.1 The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
aecf2d55-b174-4b28-b762-962b60c62ea7
< 2.5.2
MEDIUM 6.1 The HTML5 Radio Player - WPBakery Page Builder Addon plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
aeaf4844-1ca4-45c1-847b-a06bf7202426 MEDIUM 6.1 The Marquee Style RSS News Ticker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
aeacc3e5-020f-44b9-b412-c5a9114e0178
< 1.1.2
MEDIUM 6.1 An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-aj… wordfence
aea03b8f-5779-430c-b081-79af314d0cda
< 1.3.0
MEDIUM 6.1 The WP Currency Exchange Rates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
ae9b4d1f-d403-42e2-aaa0-be5459fba7a8 MEDIUM 6.1 The MG Post Contributors plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
ae970655-10a3-4917-a6d2-e9f8681c024f
< 2.7.2
MEDIUM 6.1 The Awesome Event Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
ae8e245f-2458-4ffe-8e73-bed61331f39d
< 4.0.4
MEDIUM 6.1 The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before … wordfence
ae8a316f-a9ad-451a-9892-cf5068072a78
< 2.8.0
MEDIUM 6.1 The Master Slider plugin for WordPress is vulnerable to Cross-Site Scripting via the ‘page’ parameter in versions up… wordfence
ae87b5fc-0fe5-4bc0-a18d-ea219865a0f3 MEDIUM 6.1 The Gecko 6.0 - Responsive Shopify Theme - RTL support theme for WordPress is vulnerable to Reflected Cross-Site Scripti… wordfence
ae77b00e-bbcf-4fe2-ab7f-d2e21ef54d3e
< 2.1.1
MEDIUM 6.1 A cross-site scripting (XSS) vulnerability in admin/partials/wp-splashing-admin-sidebar.php in the Splashing Images plug… wordfence
ae67f620-81d8-4f5f-93cb-153cd5c2bd90
< 1.5.6
MEDIUM 6.1 Pretty-Link WordPress plugin 1.5.2 has XSS via url parameter. wordfence
ae53b67a-1df9-499a-a232-cf7560a3cf02 MEDIUM 6.1 Reflected XSS in wordpress plugin indexisto v1.0.5 via indexisto_index parameter. wordfence
ae46d949-eca0-4cd2-b458-229c027a6c3f MEDIUM 6.1 The JK Html To Pdf plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
ae44ad5c-de2a-4217-978f-3c52c0bac55b
< 5.25.10
MEDIUM 6.1 The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… wordfence
ae411d4f-1a23-47ac-8b84-fe7c01618bae MEDIUM 6.1 The Gallery Images Ape plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
ae35a02c-ba33-478d-a054-98b486e2192a
< 1.4
MEDIUM 6.1 Cross-site scripting vulnerability in WP Booking System Free version prior to version 1.4 and WP Booking System Premium … wordfence
ae31fb73-de38-4c30-9348-80373ed6e5cd MEDIUM 6.1 The altos-connect plugin 1.3.0 for WordPress has XSS via the wp-content/plugins/altos-connect/jquery-validate/demo/demo/… wordfence
ae2e044e-444e-4328-8783-319cd01981b7 MEDIUM 6.1 The Dyn Business Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
ae24c5d8-4171-4768-a2b7-444d81bc76c9 MEDIUM 6.1 The Contact Form 7 Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
← Prev 843 844 845 846 847 848 849 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top