🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 851 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
aa178e13-b4a5-4847-ac0e-9f14f8c9b446 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in wp-plugins-net/index.php in the WP Plugin Manager (wppm) plugin 1.6.4.b and … wordfence
aa16cbeb-b3ba-4ef4-83ef-69d8ebd3738f MEDIUM 6.1 The Simple Flash Video plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.7 … wordfence
aa105250-7d19-49c9-af20-6d5e033314e6
< 2.73.1
MEDIUM 6.1 The wp-polls plugin before 2.73.1 for WordPress has XSS via the Poll bar option. wordfence
a9eed9ee-2a84-4500-8ec9-86036c257659 MEDIUM 6.1 The xili-tidy-tags plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
a9ca2bc8-8ec3-4fd2-a1ab-ee0982182623 MEDIUM 6.1 The Google Transliteration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
a9b3b5ae-b086-4068-aa05-a732f1a8f508 MEDIUM 6.1 The Social Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
a97f74bf-c3a5-4bb3-a7fd-d3f43af6ec42
< 3.10.6
MEDIUM 6.1 The Visualizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.… wordfence
a97df03d-a927-4745-b7ed-3a8402a21298 MEDIUM 6.1 The WP Login Control plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order' parameter in a… wordfence
a96da08b-f43d-4432-8c47-c86a1a1299ae
< 4.27.4
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the VideoWhisper Live Streaming Integration plugin 4.27.2… wordfence
a961d30e-f2cb-458d-8f1a-18f6e769efbc
< 2.5.1
MEDIUM 6.1 The WP Discord Invite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘webhook’ paramet… wordfence
a95f16ae-286d-474c-b85e-8d47a14d7533
< 1.7.9
MEDIUM 6.1 The Landing Page Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
a95e1164-2c48-4265-818d-4ee4e894532b MEDIUM 6.1 The Gigaom Sphinx plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
a95cbc9e-146a-4b6d-bfb7-9f7ea5ec394e
< 2.0.0
MEDIUM 6.1 The Wr Age Verification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘PHP_SELF’ para… wordfence
a946cca6-670b-4baf-a941-43d0a0261c0d
< 2.4.2
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.1 for WordPress allow remote atta… wordfence
a93f6dce-56e0-4131-ba26-65a0c6b2e9c5
< 1.0.4
MEDIUM 6.1 The Yampi Checkout plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including… wordfence
a93c0dd4-8341-438d-8730-470e9a230d97
< 2.1.77
MEDIUM 6.1 The WooCommerce Product Vendors plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
a931436c-102e-414a-9c1d-64c768be7b93 MEDIUM 6.1 The bloggie theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.8… wordfence
a923c84e-3641-45ec-970e-faea803897bf MEDIUM 6.1 The ECOBIZ <= 3.3, Ebiz <= 1.2, Avanix <= 1.2, and Ovum (unknown version) themes for WordPress are vulnerable to Cross-… wordfence
a922c2ad-77ec-4fa8-b997-fa7e85d96590 MEDIUM 6.1 The Comment Genius plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` p… wordfence
a9113601-7833-4d7a-8567-97e99b54200a MEDIUM 6.1 The SrcSet Responsive Images for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versi… wordfence
a90e1628-3490-4aac-9e82-b3b9692813f0
< 1.1.1
MEDIUM 6.1 The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg. wordfence
a8ea0559-dec7-4c20-956d-dbfe7bc67634
< 4.4.3
MEDIUM 6.1 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Reflected Cross-Si… wordfence
a8e34c05-7431-4acd-91f3-aab5e66f61ad
< 1.7.1007
MEDIUM 6.1 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
a8d67bc0-8c21-43e8-bdcc-1235eca94fa7
< 2.1.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in client-assist.php in the dsIDXpress IDX plugin before 2.1.1 for WordPress al… wordfence
a8d4dc12-ae17-477f-a8d2-da9747672a26
< 1.3.40
MEDIUM 6.1 The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form. wordfence
← Prev 848 849 850 851 852 853 854 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top