🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 852 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a8d0f29a-7c79-4e2b-8b59-44cc47293e4e
< 4.0.2
MEDIUM 6.1 The VR-Frases plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.0… wordfence
a8cdde8d-db43-4702-81c3-ea2d867baa8d
< 1.0.4
MEDIUM 6.1 The Razorpay Subscription Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting d… wordfence
a8ca195d-312b-41d2-a9d7-4d306fc800ce
< 0.8.8.6
MEDIUM 6.1 The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the wpfastestcacheoptions wpFastestCachePreload_number or … wordfence
a8c24278-c392-43c7-b50a-241d5d6fc2d9 MEDIUM 6.1 The CallPhone'r plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
a8bfdf39-2387-4a6f-ab85-6756a1e67305
< 1.9
MEDIUM 6.1 The ForumEngine theme for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and… wordfence
a8af7c85-977f-41aa-acbe-293dfa913577
< 3.4
MEDIUM 6.1 The easy-property-listings plugin before 3.4 for WordPress has XSS. wordfence
a8a5a78e-a8c2-44bd-8e91-9a03228ab079
< 3.4.0
MEDIUM 6.1 The Browser Address Bar Color plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
a88b527c-8b2d-44a3-addd-7de3bfa5f9b2 MEDIUM 6.1 The UPDATE NOTIFICATIONS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
a888a861-0028-4650-9c80-0d3ec91ba099 MEDIUM 6.1 The ReConstruction theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
a87d7770-2974-4764-a026-933850cb5173 MEDIUM 6.1 The Awa Plugins plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
a879b624-1670-40f5-832a-63c9c850a953 MEDIUM 6.1 The Blogger Image Import plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 2.1. This is due to… wordfence
a869248a-a3ff-4a5b-b980-ecd2c2aafa98 MEDIUM 6.1 The Web Push plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.… wordfence
a85eec18-49cc-44c0-ac86-ccc192a621a0
< 2.4.4
MEDIUM 6.1 The WordPress File Upload plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
a85d6b73-1e78-49bd-9530-c9d65a202c50 MEDIUM 6.1 The DN Sitemap Control plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
a858e370-a7b4-4247-9e79-548833e09ec0 MEDIUM 6.1 The Personal Favicon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
a851172f-3b27-4bc2-adc7-6863c2fd1c0a
< 5.102.0
MEDIUM 6.1 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crs… wordfence
a84d6f64-9ebb-4773-a9c1-8f23fb2801a9
< 5.7.12
MEDIUM 6.1 The Email Subscribers & Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘camp… wordfence
a846b773-82b6-47c2-aa2d-af6b1a178788 MEDIUM 6.1 The KenthaRadio theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.… wordfence
a83e68e0-1b5b-4fd5-be00-37b8f11144c4
< 7.6.3
MEDIUM 6.1 The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg… wordfence
a83c438b-ce08-42d8-b3b2-8ab12dedcf3e MEDIUM 6.1 The Pagerank tools plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
a837ed04-7643-4efe-aefc-62911b465ba9
< 6.6.2
MEDIUM 6.1 The Block Editor Bootstrap Blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
a8290783-9eb5-4fae-8b00-e3b5a5a0ed35 MEDIUM 6.1 The Media Usage WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/mmu_admin… wordfence
a82820ec-b36a-4fed-b42d-17bf26a25a4c MEDIUM 6.1 The VSTEMPLATE Creator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
a823a21e-78b5-4186-bb67-88799509970d
< 3.10.8
MEDIUM 6.1 The Yml for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter … wordfence
a81d3b09-b8dd-4697-ab43-c863e8d1e1d5
< 1.6.3
MEDIUM 6.1 The Maintenance Switch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘preview-code’ p… wordfence
← Prev 849 850 851 852 853 854 855 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top