🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 850 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
aafa8eb8-73e6-48b5-a94e-85730d6250f3
< 1.22.9
MEDIUM 6.1 The "UpdraftPlus WordPress Backup Plugin" plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '… wordfence
aaf7107c-1e9f-4020-aed3-a6a687a0cf6c
< 2.3.4
MEDIUM 6.1 The Variation Images Gallery for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via st… wordfence
aaece360-25b0-4a35-bd23-57c6591623eb MEDIUM 6.1 The Board Election plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
aae9018c-eef9-4d1b-b510-446db1644e78
< 1.5.2
MEDIUM 6.1 The Simple Presenter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
aae6058c-1a0c-48dd-9aca-9a44f06d27e5
< 2.6.1
MEDIUM 6.1 The JobSearch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.5… wordfence
aade0d5c-0fca-4477-8dae-6a43cd3c2edc MEDIUM 6.1 The Recip.ly Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
aac9be6c-7498-482e-8c38-da17a2c7f00a
< 2.9.5
MEDIUM 6.1 The RSVP Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
aac6fcee-cb8b-4862-a1f1-9af692ae741f MEDIUM 6.1 The Bulk change of posts terms and post types plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
aac3fb8e-9b92-4ed1-ac9f-50870d4c5c9f
< 3.14.23
MEDIUM 6.1 The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters lik… wordfence
aac382a7-0548-4c5a-b82b-f173ff449d23 MEDIUM 6.1 The JS Multi Hotel Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘path’ parameter in … wordfence
aac33311-86bb-4e1b-a75a-aaf26aaedfec MEDIUM 6.1 The AF Tell a Friend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
aab5879b-82e7-45c3-8b0e-25bf699f7276 MEDIUM 6.1 The Simple Modal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
aaa8c1df-d908-4ab5-8194-d9451d8efe31 MEDIUM 6.1 The Job Board Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
aa9edf84-7ba0-488c-93ca-ed0b2ee435d5 MEDIUM 6.1 The WP Ad Guru – Banner ad, Responsive popup, Popup maker, Ad rotator & More plugin for WordPress is vulnerable to Sto… wordfence
aa9c2a67-e254-4dde-9f58-81281e98cdb2
< 3.0.1
MEDIUM 6.1 The Feed Them Social plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘expires_in’ param… wordfence
aa98b83d-5c1f-4fce-b1b8-3d1796fdaef7 MEDIUM 6.1 The Mass Messaging in BuddyPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
aa8bd71f-3aae-4734-ab6e-921b112b452b MEDIUM 6.1 The iPhone Webclip Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
aa7ec0a8-b5b2-456e-be5c-05e63502fb9a MEDIUM 6.1 The Quick Localization plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
aa6c0dc9-0fcc-4d7d-8263-6e924ebabc48 MEDIUM 6.1 The GoQMieruca plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
aa3ff74a-a38e-4cb3-b0b8-99fb16185f42
< 2.5.1
MEDIUM 6.1 The Zedity – The Layout-Free Content Editor plugin for WordPress is vulnerable to Cross-Site Scripting via the 'zactio… wordfence
aa3e27ca-8837-4cd8-a233-ad1eed365f7c
< 1.4.3
MEDIUM 6.1 The reflex-gallery plugin before 1.4.3 for WordPress has XSS via Edit Content URL field. wordfence
aa3909f6-fd2f-44e7-83b5-51c8cda4b20f
< 4.76
MEDIUM 6.1 The WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket plugin for WordPress is vulnerable to Reflected Cro… wordfence
aa355718-c08f-4a22-bf6e-697af267ad12
< 1.1.5
MEDIUM 6.1 The Snazzy Maps plugin before 1.1.5 for WordPress has XSS via the text or tab parameter. wordfence
aa34fdd1-5a04-43c6-a005-17be1256b09e
< 1.8.2
MEDIUM 6.1 The Related Posts plugin before 1.8.2 for WordPress has XSS via add_query_arg() and remove_query_arg(). wordfence
aa197b6b-be18-48c2-a7e3-d921b4ef1c54
< 9.3.9
MEDIUM 6.1 The XStore theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 9.3.8 d… wordfence
← Prev 847 848 849 850 851 852 853 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top