🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 849 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ac352bb2-f624-4c31-951a-988a0b420635
< 3.2.1
MEDIUM 6.1 The Simple Social Media Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shar… wordfence
ac247d3a-9e60-431e-ac98-2601e9907758
< 1.5.6
MEDIUM 6.1 The Christmasify! plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5… wordfence
ac0b8c10-50d5-428c-8bce-0d9912a6c46d MEDIUM 6.1 The Custom Links On Admin Dashboard Toolbar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers… wordfence
abe50539-f6a9-476a-a408-4f94f7f31fcc
< 0.4.7
MEDIUM 6.1 The GTmetrix for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'report_id' and … wordfence
abe2de9c-4044-4b52-9ec8-c66691313cf0
< 3.0.7
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in question.php in the mTouch Quiz before 3.0.7 for WordPress allow … wordfence
abdbee50-b8c3-4254-a828-37629a798c92 MEDIUM 6.1 The Woocommerce Email Report plugin for WordPress is vulnerable to Unauthenticated Cross-Site Scripting via an uknown pa… wordfence
abd70095-7549-41f8-913b-528e2b215929 MEDIUM 6.1 The WP-Announcements plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
abcebcdb-e22a-4b6c-86db-f95b00260446
< 3.9.4
MEDIUM 6.1 The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… wordfence
abc14a00-5560-440b-a5ba-4ff41a6c54c3
< 3.7.7
MEDIUM 6.1 The Visualizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg with… wordfence
abbf1bb8-16db-48b6-b2ff-d828fcb7f7c7
< 2.1.4
MEDIUM 6.1 The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulne… wordfence
abb19c71-71c6-487d-b7b2-114459535af8 MEDIUM 6.1 The Implied Cookie Consent plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
aba2ad9a-9cf7-4406-a984-8c647d75a67e MEDIUM 6.1 The Theasys plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1… wordfence
aba1ca3a-a937-400b-b175-2ca4e67a107d
< 4.0.9.4
MEDIUM 6.1 The MailChimp Subscribe Forms plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 4.0.… wordfence
ab8cc5d1-8ea2-4590-90c4-6541f336b057 MEDIUM 6.1 The WCP OpenWeather plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in … wordfence
ab8a13d5-911a-4c25-8d5a-391146971c0c
< 1.6.0
MEDIUM 6.1 includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for Wor… wordfence
ab88b12a-177d-45e2-a384-7b44f09bc605 MEDIUM 6.1 The Skip To plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.0… wordfence
ab82c0ca-7728-4fae-a180-046f76d670f7 MEDIUM 6.1 The Filmix theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1 due… wordfence
ab779713-7004-47f6-af16-2db2c7c1013b
< 1.6
MEDIUM 6.1 The "WordPress Amazon S3 Plugin" plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ … wordfence
ab710963-64e2-476e-9a60-0a18b64b7550
< 3.7.18
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in W… wordfence
ab58a6e8-624b-4268-a95a-0e004f8e8c86
< 8.0.06
MEDIUM 6.1 The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field. wordfence
ab573de3-e05a-4946-8734-8cb18d05ad69 MEDIUM 6.1 The افزونه پیامک حرفه ای فراز اس ام اس plugin for WordPress is vulnerable to Reflected Cross-… wordfence
ab3ea93a-521a-45af-ac67-9f4417f3db59
< 14.13.3
MEDIUM 6.1 The cformsII plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 14.13.2 due to… wordfence
ab15e532-406d-4e6f-ab5e-ae3631acc073 MEDIUM 6.1 The WordPress Logging Service plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
ab0cc008-be18-4703-8156-acb00c1ac9a7 MEDIUM 6.1 Cross-site request forgery (CSRF) vulnerability in deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0… wordfence
aafe218d-a0c4-4346-b2cd-4beb0d1fc010 MEDIUM 6.1 The Simple Custom post type custom field plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… wordfence
← Prev 846 847 848 849 850 851 852 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top