πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 853 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a813ede7-2660-4dbb-80e0-68b22e5a116c
< 1.1.20
MEDIUM 6.1 The Booking Ultra Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
a80d13c7-21e4-4cb5-b28d-340668732c0a
< 1.6.5
MEDIUM 6.1 The TubePress plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to 1.6.5 due to insufficient inp… wordfence
a7ffc02d-190b-4494-a43f-1825914145ff
< 2.2.4
MEDIUM 6.1 The CURCY plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.3 d… wordfence
a7ea99e7-2502-42a2-b037-2040114a8055
< 1.3
MEDIUM 6.1 Multiple cross-site request forgery (CSRF) vulnerabilities in the Our Team Showcase (our-team-enhanced) plugin before 1.… wordfence
a7da2b5d-8e0c-492a-a6a6-7302cd277d0b
< 1.4.2
MEDIUM 6.1 The Quick Restaurant Reservations plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several para… wordfence
a7c7267e-81b2-4a03-b1fc-254b8233d6d0 MEDIUM 6.1 The Widget4Call plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, … wordfence
a7ae4294-3f20-4f97-ae74-858121280c01 MEDIUM 6.1 The Source theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and output e… wordfence
a7a39309-f066-4d4c-9fe1-f6d3c268b51e MEDIUM 6.1 The WP Easy Post Mailer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
a79c783f-9581-449d-a431-022b30af0d39
< 1.5.8
MEDIUM 6.1 The Beacon Lead Magnets and Lead Capture plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all ver… wordfence
a7982828-bc67-48ee-be80-3203b081e29b
< 0.6.0
MEDIUM 6.1 The broken-link-manager plugin before 0.6.0 for WordPress has XSS via the HTTP Referer or User-Agent header to a URL tha… wordfence
a78da5c5-fb12-4fc9-8c51-6d9f6f7a4043
< 3.1.0
MEDIUM 6.1 The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
a78321b7-b62b-40ab-a15d-037ebd905d8b MEDIUM 6.1 The CPT Bootstrap Carousel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
a77f8a2b-c61b-4942-93b5-202ebce4cf96
< 1.3
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in pages/admin/surveys/create.php in the WP Survey And Quiz Tool plugin 1.2.1 f… wordfence
a7795c3c-17fc-48aa-ae22-cbf6e241275e MEDIUM 6.1 The Amazon Product Price plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
a76ded81-4c78-4054-9a26-7e215285a2b6
< 3.6.1
MEDIUM 6.1 The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
a759f4f4-6e0b-4754-b5b5-d110a050d0ba
< 1.1.43
MEDIUM 6.1 The photoblocks-grid-gallery plugin before 1.1.43 for WordPress has wp-admin/admin.php?page=photoblocks-edit&id= XSS whe… wordfence
a7566ac1-9ae2-44d2-8ad1-029957870992
< 2.3.1
MEDIUM 6.1 The Subscribe to Comments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_que… wordfence
a753b4ba-9223-4eff-95e3-da7a1b2830a6
< 6.0.3
MEDIUM 6.1 The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS. wordfence
a752e211-5ae2-4b85-ac01-872dc829d84c
< 6.9.21
MEDIUM 6.1 The Advanced Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
a74d6b36-e0f1-4cfb-b1e9-0573081ed975 MEDIUM 6.1 The WDSocialWidgets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all… wordfence
a7427a8e-df7c-4a9f-ab6f-b856afef003a MEDIUM 6.1 The Extra Privacy for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
a73089ab-a6df-4e3e-8d50-4add718e8c9d MEDIUM 6.1 The Wishlist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.1.… wordfence
a7287c26-82c7-40d9-92a2-5102b65ba432 MEDIUM 6.1 The Scroll Top – WordPress Scroll to Top plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all v… wordfence
a720fce1-25d6-4cab-96e2-99365b2148b5 MEDIUM 6.1 The Bing Search API Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
a7181056-d2ee-4c0f-b9a8-fdb7ad042a6b
< 2.2.41
MEDIUM 6.1 The FooGallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.… wordfence
← Prev 850 851 852 853 854 855 856 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top