πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 857 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a3d4e7bb-9e9b-4a0e-ab6d-c769dd957748 MEDIUM 6.1 The Google XML News Sitemap plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
a3bdccfd-6b82-4a76-81f1-eb0f6d62d413 MEDIUM 6.1 The Slideoptinprox plugin for WordPress is vulnerable to Cross-Site Scripting via the 'id' parameter in the 'ar_submit.p… wordfence
a3ba495f-787a-4a9a-ada7-d3c5670aa14e MEDIUM 6.1 The WP-Basics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0… wordfence
a3b459e0-4bd9-443e-96e4-91663a35c26e
< 1.1.1
MEDIUM 6.1 The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
a3b07f91-c96a-49a5-8ffc-90f34d93aa91
< 2.9.1
MEDIUM 6.1 The Netgsm plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.… wordfence
a385d286-c15c-4e95-b360-fec1ec455b47
< 3.4.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in js/ta_loaded.js.php in the Traffic Analyzer plugin, possibly 3.4.1 and earli… wordfence
a385415d-ec00-4cac-962c-8462c8bb13f1 MEDIUM 6.1 The Visitor Details plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
a36e7b70-dd2e-4846-bad2-aa225cb60a8e MEDIUM 6.1 The AdsMiddle plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
a35499cd-9849-4b1f-816b-3e71a7b1bbeb MEDIUM 6.1 The SlideDeck 1 Lite Content Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions… wordfence
a341bcc4-fe5b-452d-aa93-4e3dd8d42403
< 1.5
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in searchform.php in the AndyBlue theme before 1.5 for WordPress allows remote … wordfence
a33cc275-aa0d-4b8b-863a-6a32fac37512
< 9.0.3
MEDIUM 6.1 The teachPress for WordPress is vulnerable to Reflected Cross-Site Scripting via the meta_field_id and cite_id paramete… wordfence
a33c5bf1-386f-42ba-88aa-e9206d943ea8 MEDIUM 6.1 The Ni CRM Lead plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
a3302110-60ae-4ad1-8a8c-3511027da3a8
< 1.2
MEDIUM 6.1 The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter. wordfence
a32c6c0c-4a4a-44c7-9724-153467699b3a
< 11.6.1
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cformsII(cforms 2) Word… wordfence
a329cf0a-8800-470a-9657-452f26112956
< 1.2.6
MEDIUM 6.1 The BBP Core – Expand bbPress powered forums with useful features plugin for WordPress is vulnerable to Reflected Cros… wordfence
a323ccb8-c461-4203-a590-3785594b90f5 MEDIUM 6.1 The PPO Call To Actions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
a31ab564-48b7-44f7-a1da-226222c3fd7b MEDIUM 6.1 The Cookie Params plugin for WordPress is vulnerable to Reflected Cross-Site Scripting and Cross-Site Request Forgery du… wordfence
a309d8d3-bc1c-4301-8da9-ce7df7c2f76f
< 0.0.6.6
MEDIUM 6.1 The Encrypted Blog plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' parameter … wordfence
a2fe6b69-7a89-4cd4-8a8c-f7e1e587fbbe
< 2.18
MEDIUM 6.1 Rav Messer's Ravpage <= 2.16 is vulnerable to Cross-Site Scripting exploitable by unauthenticated attackers. Versions up… wordfence
a2f9fec5-d6d8-4317-bd40-810cd37a3158 MEDIUM 6.1 The Legal + plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1… wordfence
a2f646fb-b089-492d-9d90-0f43b18e1a90
< 4.5.2.9
MEDIUM 6.1 In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search… wordfence
a2ed28cd-44e6-416a-a252-8341104f5ef3
< 3.3.1
MEDIUM 6.1 The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 3… wordfence
a2e847fd-0932-4d65-a201-b86e39a33588
< 5.9.4
MEDIUM 6.1 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
a2e35679-278e-4e7d-b366-fe7d8cba7930
< 2.2.5
MEDIUM 6.1 The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to Reflected Cross-Sit… wordfence
a2e1948a-9513-43e4-aadd-369a7f4dc137
< 2.0.33
MEDIUM 6.1 The Ultimate Member plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
← Prev 854 855 856 857 858 859 860 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top