🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 847 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ae1820ab-6a24-45b3-801c-34c5515c8868
< 1.4.2
MEDIUM 6.1 The Modern theme before 1.4.2 for WordPress has XSS via the genericons/example.html anchor identifier. wordfence
adffa925-0d91-4c8a-b9ec-1af10cb882ca MEDIUM 6.1 The Authentication and xmlrpc log writer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… wordfence
adfe66d7-5402-447f-bca2-8de5b6447cbb MEDIUM 6.1 The Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart plugin for WordPress is vulnerable to Cros… wordfence
adf8c50a-c657-4452-8c6b-23c2a56b7b78 MEDIUM 6.1 The Word Freshener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
adf5b377-f4b6-4859-a5a2-2cb8f61b7e81 MEDIUM 6.1 The Forge – Front-End Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
adee74ec-7a3c-4519-bea8-23c92e89d484 MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in payper/payper.php in the Pay Per Media Player plugin 1.24 and ear… wordfence
ade7da50-49f3-4026-a2c0-5c23c9b0f0cb MEDIUM 6.1 The Admin Menu Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘role' GET parameter in ve… wordfence
addf264e-e23c-4bb6-a898-0fbb4ec28189
< 5.9.5.5
MEDIUM 6.1 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scr… wordfence
add32c06-90d0-466f-b176-aaae55cf03fb MEDIUM 6.1 The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
adcaf2db-2026-46bb-8fbc-0400d7c1e296
< 2.4.1
MEDIUM 6.1 The Stock Sync for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ p… wordfence
adc7e02f-aa95-417f-8778-d9a75beeaf13 MEDIUM 6.1 An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. A cross-site scripting (XSS) vulnerability allows rem… wordfence
adc2ce12-6be2-447d-a05d-da36ce7f5727
< 0.9.8
MEDIUM 6.1 The Admin Options Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
adbf25c2-b572-4a83-811e-3a5dda1ad8cd
< 2.0
MEDIUM 6.1 The Pinfinity theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in versions … wordfence
adbebe61-3adc-4ba1-8767-863dc2310cad MEDIUM 6.1 The Gift Certificate Creator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘receip_addr… wordfence
adbc8d10-4088-4918-b01e-86554512c7a4 MEDIUM 6.1 The Off Page SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
ad8f8c41-a3b9-4287-b6b2-489fb77b7553
< 4.6.1
MEDIUM 6.1 The Albo Pretorio Online plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Errore’ param… wordfence
ad8311d4-b07d-4e74-ab14-69faa3e409c8
< 1.15.27
MEDIUM 6.1 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Refle… wordfence
ad81c6b6-dbf5-40a3-894d-e2fbab69d38a MEDIUM 6.1 The Domain Replace plugin for WordPress is vulnerable to Cross-Site Scripting via the msg parameter found in the ~/domai… wordfence
ad7eee97-332a-4f3c-bba1-d108a769599d
< 1.9.12
MEDIUM 6.1 The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attrib… wordfence
ad7e3fe0-561e-40d8-b22c-bf8e7675b87f
< 2.17.3
MEDIUM 6.1 The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in t… wordfence
ad5ca2a1-06ac-4f26-9ecb-bb861c035f57 MEDIUM 6.1 The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network s… wordfence
ad5c8eb8-8e58-4bed-a39c-b54e2cfd9cd3
< 3.3.0
MEDIUM 6.1 The 15Zine WordPress theme before 3.3.0 does not sanitise and escape the cbi parameter before outputing it back in the r… wordfence
ad40de6a-744c-4a78-912a-4fd76ae75dc1 MEDIUM 6.1 The BruteGuard – Brute Force Login Protection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in … wordfence
ad3644a7-3999-49f8-822c-9e3b22bf7b8f MEDIUM 6.1 The ez Form Calculator - WordPress plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versio… wordfence
ad306c2b-5fc7-49c2-9ee0-777c7e6014e5 MEDIUM 6.1 The Full Circle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0… wordfence
← Prev 844 845 846 847 848 849 850 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top