🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 848 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ad254899-983b-42bc-a248-7dbf9003d06c
< 0.983
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in views/video-management/preview_video.php in the S3 Video plugin before 0.983… wordfence
ad24e14c-a5b1-4c45-8b00-2625f32ad6ce
< 1.2.6.9
MEDIUM 6.1 The Marketing Automation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
ad177f89-2cc0-4ab3-a787-3b0bd3bf3e47
< 8.9.2
MEDIUM 6.1 The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before output… wordfence
ad0e5a96-903b-4de4-be57-6236dcebaa94 MEDIUM 6.1 The Asgard Security Scanner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'asgard_authkey… wordfence
acf9dfaf-4a4e-4ff1-8276-94b1ffb76ab1 MEDIUM 6.1 The WpStickyBar – Sticky Bar, Sticky Header plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t… wordfence
acde42e4-7445-427a-b4fa-9ef225049bb8
< 1.0.8
MEDIUM 6.1 Reflected XSS in wordpress plugin whizz v1.0.7 via plugin parameter. wordfence
acdac8a7-6ac5-481d-a636-dd791fda89a3
< 2.6.0
MEDIUM 6.1 The Contact Form Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the id parameter in … wordfence
acd61330-eba8-4311-8b60-30c3124067f0
< 1.2.2
MEDIUM 6.1 The WP Hardening – Fix Your WordPress Security WordPress plugin before 1.2.2 did not sanitise or escape the $_SERVER['… wordfence
acd0349b-7864-4e4e-84ba-6f0ec5b585f3 MEDIUM 6.1 The UserPlus plugin for WordPress is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce… wordfence
acca5aad-9029-452d-8701-34387202784e MEDIUM 6.1 The iBuildApp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
acb8c11f-e175-4361-b016-e1ebc1713be0
< 3.6.2
MEDIUM 6.1 The ShortPixel Adaptive Images plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a debugging para… wordfence
acb4d5e7-25bf-4c06-ba0b-2404062dfbb8 MEDIUM 6.1 The Automatic Ban IP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
acb44af7-2fa9-49d7-8e87-80b93c2db005
< 2.4.8
MEDIUM 6.1 The Autoglot – Automatic WordPress Translation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
aca092cf-9482-468e-8dd4-af04e25bcf33
< 4.2.2
MEDIUM 6.1 The Primer MyData for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'img_src'… wordfence
ac9ed78b-a09d-46b0-871e-db5208b28ccf MEDIUM 6.1 The Tactical Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
ac9ea266-d3a5-4140-9bee-86de031ca4e7 MEDIUM 6.1 The Fix Multiple Redirects plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
ac96d3c5-1409-47f7-9e8e-0c35aa8199ce MEDIUM 6.1 The Everest News plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
ac7d6023-335c-45ce-a87b-0bd476b251d9 MEDIUM 6.1 The MDC Comment Toolbar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
ac7aca5f-657d-45a9-bb10-f3e75dc3eeba
< 4.0
MEDIUM 6.1 The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape… wordfence
ac702c3b-01d6-40ef-a18c-380185667a98
< 1.3.1
MEDIUM 6.1 The Track, Analyze & Optimize by WP Tao plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in vers… wordfence
ac6c6ce4-9944-4c8e-89aa-6a2e870ef205
< 1.3.60
MEDIUM 6.1 The Royal Elementor Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
ac63e451-2ab3-4ca9-bb69-a0ef04fef3a9 MEDIUM 6.1 Multiple cross-site request forgery (CSRF) vulnerabilities in the Simplelife plugin 1.2 and earlier for WordPress allow … wordfence
ac4f9453-f3d9-4ef5-8c4e-1d51ad194342 MEDIUM 6.1 The Plum: Spin Wheel & Email Pop-up plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing c… wordfence
ac3a359c-bdcf-42c5-9e54-c704a358b561
< 1.1
MEDIUM 6.1 Cross-site request forgery (CSRF) vulnerability in the Encrypted Contact Form plugin before 1.1 for WordPress allows rem… wordfence
ac381ed7-ff6a-4fbc-965b-80f3804b3c5f
< 3.5.1
MEDIUM 6.1 The Afterpay Gateway for WooCommerce plugin is vulnerable to Reflected Cross-Site Scripting via the ‘orderToken’ par… wordfence
← Prev 845 846 847 848 849 850 851 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top