🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 858 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a2c9b82a-b63c-4647-a561-d567b6e9ff0a
< 3.4.5
MEDIUM 6.1 The Discounts Manager for Products plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wcdp_… wordfence
a2bf6102-458f-4930-8880-baa96afb1c15
< 2.4
MEDIUM 6.1 The Auto Featured Image from Title plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o… wordfence
a2b317f7-b7b6-45d0-b8bf-29f70669db51
< 2.7.7
MEDIUM 6.1 The Chartify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.7.… wordfence
a2ac27b5-88d5-43d5-a4bb-c2948ffc50f0 MEDIUM 6.1 The Clipta Video Informer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘w’ parameter… wordfence
a292239a-0848-4770-8993-2cff5ef16eaa MEDIUM 6.1 The Mancx AskMe Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
a2887dbf-7d88-45da-afa5-e89dfa8bae21
< 1.0.19
MEDIUM 6.1 The AWcode Toolkit plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
a27d7c0b-81d4-4e7a-a7b4-96c0a02b6264
< 2.2.0
MEDIUM 6.1 The Deliver via Shipos for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … wordfence
a272e12b-97a2-421a-a703-3acce2ed8313
< 1.0.2
MEDIUM 6.1 The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
a26c9171-54d3-41fb-a3a7-95729437323b MEDIUM 6.1 The REVE Chat – AI-powered Chatbot & Live Chat Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site R… wordfence
a266e003-3a0a-4832-a88b-60c2a26b387c
< 1.7.4
MEDIUM 6.1 The Digital License Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remov… wordfence
a25b2187-2ba8-4332-9f96-a003edd97ff6
< 2.0.4
MEDIUM 6.1 The ARS Affiliate Page Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'utm_keyword'… wordfence
a243fbde-951b-43e0-a432-c92ae4b04c26
< 5.9.2
MEDIUM 6.1 The TheGem theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions … wordfence
a2423bdc-71ea-4328-a6a4-f79a0a446f26
< 1.5.2
MEDIUM 6.1 The Loobek theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 1.5.2 due to insufficie… wordfence
a22fa7f8-f5d0-4007-8e4e-0185659a95d6 MEDIUM 6.1 The Mandrill WP – Email Form Under Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
a222c714-7c54-4c86-b6af-abdfeb966250
< 2.5.3
MEDIUM 6.1 The Pz-LinkCard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
a21b5306-e6b3-4186-a001-eb280c8d104c MEDIUM 6.1 The Já-Já Pagamentos for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … wordfence
a217794b-9da3-4286-a851-79b33c6b7e99 MEDIUM 6.1 The WordPress Signature plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
a2096af8-1a09-4839-a9db-ce7ddd552b06 MEDIUM 6.1 The Find Your Reps plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
a2072bac-4ca1-4342-beb7-abd145aeef48
< 7.5.8
MEDIUM 6.1 The Themify Builder plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7.5.7. Thi… wordfence
a201e33b-bec2-4d84-8d05-9860bc37203d MEDIUM 6.1 The Comment-Emailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
a200bb51-09bd-4eaa-8a57-93c3515f720c MEDIUM 6.1 wordfence
a1fa6b6b-c49f-4ad5-8b56-6c122af94a11 MEDIUM 6.1 The Sello ChannelConnector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
a1f2925e-033e-46aa-9a61-bddc0f350d5c MEDIUM 6.1 The Custom Widget Classes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
a1f153bb-87b0-4dc7-b014-776ab20ad8c3
< 2.14
MEDIUM 6.1 The Vampire Character Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… wordfence
a1eed70b-d12e-4b7f-afc1-7037f5c406b8
< 1.8.0
MEDIUM 6.1 The Contact Form by Supsystic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
← Prev 855 856 857 858 859 860 861 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top