ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 859 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a1d0e3be-4f3e-4f33-8511-a15d9183e878 MEDIUM 6.1 The RomanCart On WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
a1cb99dc-31a7-4d0f-afee-ca8c04cee5fe
< 3.0.1
MEDIUM 6.1 The WooCommerce PDF Invoices & Packing Slips plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ver… wordfence
a1c755aa-5f68-4f55-be88-094b0828ebec
< 4.1.8
MEDIUM 6.1 The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versi… wordfence
a1c2e4e5-472f-4517-90f0-8f7057d24ef8
< 1.8
MEDIUM 6.1 The Admin Font Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'size’ parameter in… wordfence
a1b8ac82-4c2d-44bf-ac9e-1c1abead0613
< 1.4.1
MEDIUM 6.1 Wordpress Plugin Store / AccessPress Themes WP Floating Menu V1.3.0 is affected by: Cross Site Scripting (XSS) via the i… wordfence
a1b4b36e-c1d1-4a49-88a9-36a59b6265fb MEDIUM 6.1 The Admin SMS Alert plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
a1b0d129-1070-4399-8a1e-3d3ad34dc1a2 MEDIUM 6.1 The NV Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6… wordfence
a1ada4cc-aded-4592-b0e7-f70f845c858e
< 3.0.3
MEDIUM 6.1 The Resca theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.0.2 du… wordfence
a1a1c5e7-75a4-4ca5-9707-4076b92e0c33
< 3.2.4
MEDIUM 6.1 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of … wordfence
a19bff99-b680-40a6-8a5c-7a0233b293ac
< 6.2.8
MEDIUM 6.1 The Fattura24 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in version… wordfence
a195af52-62f7-46a1-b161-280d455b71f4 MEDIUM 6.1 The EditionGuard for WooCommerce – eBook Sales with DRM plugin for WordPress is vulnerable to Reflected Cross-Site Scr… wordfence
a195892b-75d3-4a5d-86e1-4eb4b9f62624 MEDIUM 6.1 The Akismet Privacy Policies WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter befor… wordfence
a193392a-ef6d-4232-a8c9-c980bd369d5e MEDIUM 6.1 The Brightbox theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and outpu… wordfence
a186ca14-5cfd-4ce8-b73e-3881445069d7 MEDIUM 6.1 The Spice Starter Sites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
a1818e80-e580-45d4-88ab-018cb1723947
< 1.8.22
MEDIUM 6.1 The ultimate-faqs plugin before 1.8.22 for WordPress has XSS. wordfence
a15fd2da-5897-4eb8-81c3-79e800e94122
< 2.662
MEDIUM 6.1 The Flat PM plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.661… wordfence
a15ee50d-ee64-49b4-bbd2-2d0f3683a4c5 MEDIUM 6.1 The Shapeless theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and outpu… wordfence
a15e9c3d-d881-4795-a43a-c4afa6f785a6 MEDIUM 6.1 The Dropify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.6.9… wordfence
a1549c84-bba0-4b55-9b82-5b98ac4465c0 MEDIUM 6.1 The Infugrator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
a1513296-f7f6-468c-ac96-5f55812d943e
< 5.4.7
MEDIUM 6.1 The Ivory Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versio… wordfence
a14ff78b-e475-4cb0-aa23-c76392af8d7c MEDIUM 6.1 The Wc Recently viewed products plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
a14eaed7-68e0-42bd-ae67-495720743cd5 MEDIUM 6.1 The mEintopf plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … wordfence
a145f3ca-2c38-4058-9aa9-e2dcc43c029a
< 1.3.2
MEDIUM 6.1 The WP Bulk Delete plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
a143eb71-d039-441b-871e-d1c5cefb0529 MEDIUM 6.1 The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' par… wordfence
a1325f47-5bcc-42cb-8eb1-c11075b5da42
< 1.0.8
MEDIUM 6.1 The WP Templata plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
← Prev 856 857 858 859 860 861 862 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top