πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 856 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a506ad5b-e88d-4264-84d7-fa6c41026c36
< 1.1.17
MEDIUM 6.1 The Qtranslate Slug plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to… wordfence
a4ffc179-f3ab-4ae1-b7e9-13535d104593
< 3.0.31
MEDIUM 6.1 The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder. wordfence
a4edf216-1ee2-41cf-b9dd-6b2b9f96ec0e MEDIUM 6.1 The imPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.1.4… wordfence
a4e343eb-b83d-43bf-a26d-db10dac18099
< 3.2.4
MEDIUM 6.1 The Video Posts Webcam Recorder WordPress plugin before 3.2.4 has a reflected cross site scripting (XSS) vulnerability i… wordfence
a4d91b01-5034-42b5-857f-c66c875dd562
< 12.0.9.2
MEDIUM 6.1 The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter i… wordfence
a4d7cab5-1641-4ed3-92c7-ad7594dcb74b
< 2.8.14
MEDIUM 6.1 The Campaign Monitor for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions … wordfence
a4ce7dc7-30f5-4629-ad14-acbfb000ee6d MEDIUM 6.1 The Calendi plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1… wordfence
a4c21c56-c424-4667-a281-fa9e7241d8ad
< 5.10.2
MEDIUM 6.1 The Better Click To Tweet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
a4b205ab-f042-46d9-a331-f18809477384
< 2.0.1
MEDIUM 6.1 The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versi… wordfence
a4a79c36-8371-4035-8c21-4bc0296fa12a
< 3.8.1
MEDIUM 6.1 The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS. wordfence
a4a4b064-4a93-4aa4-8052-f168302a0a9b MEDIUM 6.1 The Ui Slider Filter By Price plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… wordfence
a4a273e7-eb8a-4cfa-80c2-f87d04a6a33e MEDIUM 6.1 The WP Report Post plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all … wordfence
a4953b95-e013-482c-bcc7-1a95f8941624
< 1.5.0
MEDIUM 6.1 The WordPress Multisite Content Copier/Updater WordPress plugin before 1.5.0 does not sanitise and escape the wmcc_conte… wordfence
a46c09a5-5127-4970-a009-b5fdc9414e81 MEDIUM 6.1 The Supra CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.3. … wordfence
a463c5be-13d9-45d8-b43e-54ab188c151a
< 4.7.3
MEDIUM 6.1 The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter … wordfence
a43ffb6e-8044-4496-9496-11fa8e52a044
< 5.5.7
MEDIUM 6.1 The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues. wordfence
a41226ab-9732-4de2-843b-284c011c9224 MEDIUM 6.1 The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
a410fd9b-f3e8-4a5d-a360-10c6586b951e MEDIUM 6.1 The Sale with Razorpay plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
a40944fa-9729-4d34-adc0-857bf00d6666
< 1.14.6
MEDIUM 6.1 The "VDZ CallBack Plugin" plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in… wordfence
a401db3e-2cf2-4283-bfbe-d4a9587966e1
< 5.6.2
MEDIUM 6.1 The Jock on air now plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜$_SERVER['PHP_SELF']… wordfence
a4000749-b25f-43a7-95a0-14b4410f2301 MEDIUM 6.1 The SexBundle plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
a3f9ed8b-598e-4fac-9ed1-14ad79680f86 MEDIUM 6.1 The Neoforum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0 … wordfence
a3f0f224-f1e6-4706-9db1-d9ee59b24fc8 MEDIUM 6.1 The IE CSS3 Support plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
a3e8e42f-8ee5-40ff-934f-b7d580bc5548
< 3.9.0
MEDIUM 6.1 The Careerfy theme plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to 3.9.0 due to insufficien… wordfence
a3e095b5-9c0b-45ac-a78d-e50feda348cb MEDIUM 6.1 The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
← Prev 853 854 855 856 857 858 859 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top