🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 855 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a5e6817c-02e7-4d28-9446-c316a9ff8cbe
< 0.5.7-beta
MEDIUM 6.1 The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS. wordfence
a5e4f40b-c028-4283-ba02-c77408136713
< 3.2.6
MEDIUM 6.1 The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Reflected Cross-Site S… wordfence
a5e14205-d31d-414b-aff2-22f589dbf04c MEDIUM 6.1 The 3D Cover Carousel WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/cov… wordfence
a5dbb126-e8a1-42d0-9a05-c2e5d5da4ee1 MEDIUM 6.1 The Quote Tweet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0… wordfence
a5bcf040-cc43-4b3d-a6fc-d41973725af6
< 3.3
MEDIUM 6.1 The WordPress Bitcoin Payments – Blockonomics plugin is vulnerable to reflected Cross-Site Scripting via the 'filter_b… wordfence
a5bb8804-0b90-44c3-bf74-bbc6b4baf229
< 0.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in index.php in the WP-FaceThumb plugin 0.1 for WordPress allows remote attacke… wordfence
a5b6a66f-06fc-4b89-9f2e-9830664910f8
< 5.3.5
MEDIUM 6.1 The Grand Conference theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
a5a739d5-648f-4d79-ac37-335e89127d90
< 1.04
MEDIUM 6.1 The ILLID Share This Image plugin before 1.04 for WordPress has XSS via the sharer.php url parameter. wordfence
a5a34838-fdc5-4954-9576-abf81cbaac2e
< 2.0.28
MEDIUM 6.1 The MainWP Child plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.0.27 due… wordfence
a5a21b3a-a60f-4083-a474-ec9fedd9b8cb MEDIUM 6.1 The Mollie for Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parame… wordfence
a595f862-64af-4055-aa13-5e8f4eb3f721
< 4.4.11
MEDIUM 6.1 The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect… wordfence
a58685a5-d57a-42c9-86c7-344015952885
< 3.35
MEDIUM 6.1 The Contact Form By BestWebSoft plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includ… wordfence
a5862e5e-8506-41d0-9ed3-960548bac3e0 MEDIUM 6.1 The Flash Show And Hide Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
a56a2910-0aa7-4a8c-921d-ed7bb817846b MEDIUM 6.1 The WSAnalytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
a5454bc2-0581-45bd-8dbc-5a2819202690
< 5.1.0.3
MEDIUM 6.1 The Custom Contact Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an arbitrarily supplie… wordfence
a541f0db-d41f-4827-b311-815cab9f9bf8
< 1.4.8
MEDIUM 6.1 The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and success… wordfence
a5381944-f12c-41e6-be47-bd258da5600b MEDIUM 6.1 wordfence
a5368894-3277-47d0-8fad-adfb8df4fa93
< 5.6.12
MEDIUM 6.1 WordPress Core is vulnerable to Reflected Cross-Site Scripting via the ‘success_url’ and 'reject_url' parameters whe… wordfence
a534d51d-2bf8-40ab-a043-88c5f14542b9 MEDIUM 6.1 The IntoTheDark theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
a53291f9-632c-4b0b-b5f9-d247134f2a5c
< 3.6.3
MEDIUM 6.1 The Shortlinks by Pretty Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post_stat… wordfence
a52ed75b-07ce-46dc-8321-d10074ce0f61
< 3.3.2
MEDIUM 6.1 The WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds plugin for WordPress is vulnerable to Re… wordfence
a52e048d-6aec-4e97-8272-748aaee76b57 MEDIUM 6.1 The WooCommerce Registration Fields Plugin - Custom Signup Fields plugin for WordPress is vulnerable to Reflected Cross-… wordfence
a52dc13f-50b3-4aa3-9924-beb75351673e
< 3.7
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in admin/walkthrough/walkthrough.php in the Design Approval System plugin befor… wordfence
a5205717-af90-4d55-b812-38ded2b0f700
< 1.4
MEDIUM 6.1 The Kindeditor For WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the swfupload.swf … wordfence
a514558c-4ccc-42cf-920e-7c73c80df28e MEDIUM 6.1 The CarePlus - Health & Medical Responsive WordPress Theme for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
← Prev 852 853 854 855 856 857 858 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top