πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 854 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a713e54b-524a-451f-b17a-a2c47e087bdc MEDIUM 6.1 The Opor Ayam theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.8 … wordfence
a713c7d3-06ce-4d65-9766-2b0331656ae6
< 3.5.3
MEDIUM 6.1 The "Popup Like box – Page Plugin" plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several pa… wordfence
a6e70e5f-6b4b-40c1-b43c-957ca97e162a
< 2.1.14
MEDIUM 6.1 The WP Armour – Honeypot Anti Spam plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up… wordfence
a6e41dee-bb4a-404d-9aed-608f8f69ee94 MEDIUM 6.1 The CRUDLab Like Box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
a6d22101-06ef-4492-8ba9-8cf2ca1f4474 MEDIUM 6.1 The Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platforms plugin for WordPress is vulnerable to… wordfence
a6cefbdb-a453-4858-af7f-386a75ec592c
< 3.2.2
MEDIUM 6.1 The Alphabetic Pagination plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
a6b16ffe-1c65-49d3-9e30-407bc75d7d49
< 1.0.16
MEDIUM 6.1 The Easy Testimonial Slider and Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searc… wordfence
a6a1e7c1-0ff1-4d59-ac60-35790bf0318e
< 1.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in the Ebay Feeds for WordPress plugin 1.… wordfence
a69e6ca8-efd6-4b89-ae63-b320f9936842
< 2.2
MEDIUM 6.1 The Portugal CTT Tracking for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versio… wordfence
a691a44d-0a33-4f13-9afe-255c557ee10f
< 1.0.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows rem… wordfence
a68ca792-6870-4e28-b118-ee1125842955
< 5.21.0
MEDIUM 6.1 The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to… wordfence
a68c9151-9e1d-41d1-ae50-b59d1c833b29 MEDIUM 6.1 The Genki Announcement plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
a66904db-8f6a-4a77-86fe-1c95d3697f0d
< 4.5.6
MEDIUM 6.1 The WC MyParcel Belgium plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
a6635a04-b5fa-4cae-9567-b1d6ed688670 MEDIUM 6.1 The OZ Canonical plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
a6627f96-63d6-4f22-9eb7-fb42e748ae38 MEDIUM 6.1 The WPDBSpringClean plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all … wordfence
a646ebe5-3445-4e9b-99a9-23761d4fba9c
< 1.04
MEDIUM 6.1 The Comment Fields plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
a6381d4c-1cb6-42b6-bda3-7656400deae9
< 9.11.1
MEDIUM 6.1 The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is… wordfence
a636bc83-e41f-4620-a0f2-1de17ab64f52 MEDIUM 6.1 The Universal Analytics Injector plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
a627f10a-1463-4e4b-98a9-2008fa76e25a MEDIUM 6.1 The Meris theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.1.… wordfence
a6264dbb-81a9-43fe-908d-86e532d4b848
< 2.1.16
MEDIUM 6.1 The Arconix Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
a6240290-4b6c-46ba-9f78-e6bba3504f17
< 2.3
MEDIUM 6.1 The WP Categories Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in … wordfence
a62186aa-19aa-445b-8fdc-b029bdafd58f MEDIUM 6.1 The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
a60bb585-3c71-4381-8ba7-28ee63abdb14
< 1.1.1
MEDIUM 6.1 The Knews Multilingual Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜ff’… wordfence
a6074c97-619d-4f47-97c7-781c7a38019d
< 2.0.10
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in th… wordfence
a5f8fb20-7465-403e-af3a-4063bf5bc6ae
< 1.2.2
MEDIUM 6.1 The Oracle Cards Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
← Prev 851 852 853 854 855 856 857 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top