🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 860 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a12ccd08-ee29-4fb9-9075-cf71dc488ffc MEDIUM 6.1 The Footer Text plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.3… wordfence
a1211a41-3ab5-4ae9-84eb-0079ac54b28d MEDIUM 6.1 The Texteller plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
a10da173-9b88-4599-928d-71fc42b35c50
< 3.5.7
MEDIUM 6.1 The WPify Woo Czech plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of '$_SERVER['PH… wordfence
a0fa6d9f-7243-4349-9c79-00199ee84c25
< 4.9.4
MEDIUM 6.1 The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versio… wordfence
a0eed0fd-8841-41d1-80fb-dd02f2a1edf3
< 1.1.10
MEDIUM 6.1 The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outp… wordfence
a0d8ec3e-b16c-416f-ac18-93ecb5a63313
< 8.0.1
MEDIUM 6.1 The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Reflected Cross-… wordfence
a0cd4441-7e25-46dd-82ff-91d10b8eacd8
< 1.7.4
MEDIUM 6.1 The I Plant A Tree plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
a0c4ef62-1274-4cf3-88fc-ccabedbbe26c
< 2.8.12
MEDIUM 6.1 The Yellow Yard Searchbar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_que… wordfence
a0b14d91-f8f9-41df-b2eb-12792fb3a197
< 1.9.6
MEDIUM 6.1 The Tutor LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versi… wordfence
a0af6cea-a667-4339-bc9f-e4c0d0e36848 MEDIUM 6.1 The bbPress Move Topics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
a0aa2a10-da05-41e4-bbfa-938341919b5d
< 2.10.4
MEDIUM 6.1 The Easy Digital Downloads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘code’ param… wordfence
a0a43e7c-f1c1-4b29-86d9-64d4c2e8b8aa
< 5.3.5
MEDIUM 6.1 The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t… wordfence
a09771da-a423-42ba-8f59-5c3bd189d9d3
< 5.9.1
MEDIUM 6.1 The Advanced Custom Fields Pro WordPress plugin before 5.9.1 did not properly escape the generated update URL when outpu… wordfence
a0831971-3862-4774-8375-fe5870ef82d9
< 7.0
MEDIUM 6.1 The WP User WordPress plugin before 7.0 does not sanitise and escape some parameters in pages where the [wp_user] shortc… wordfence
a082a8bc-1dcc-4a5c-9a12-26a020c344ce MEDIUM 6.1 The Pages Order plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
a08046a5-69ac-430d-af0a-592305543ffb MEDIUM 6.1 The WordPress连接微博 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
a07ebb3a-d670-4339-a0a8-82ce661e2552
< 0.3.0
MEDIUM 6.1 The tarteaucitron-wp plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and excludi… wordfence
a073c2f1-88d3-4410-b9f5-45b04becbfcb
< 1.12.4
MEDIUM 6.1 The WP ERP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'employee_name' parameter in ver… wordfence
a068e411-d81f-4162-84e9-f1e9868963f9
< 1.1.9
MEDIUM 6.1 The Supreme Directory plugin for WordPress is vulnerable to Cross-Site Scripting via the 's' parameter in versions befor… wordfence
a06812c5-43db-4c32-a9fb-f7b86900a741
< 2.8.18
MEDIUM 6.1 The Contact Form DB plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'submit_time' and 'form… wordfence
a05b1d00-386f-4914-80e6-92d3e9721dc5
< 1.4.0
MEDIUM 6.1 init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS)… wordfence
a0598208-bfaf-40da-8e83-15c22a87fa06
< 3.9.9
MEDIUM 6.1 The Eventer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3… wordfence
a0365d52-8817-4b69-9df3-ac4c5bb6f4f3 MEDIUM 6.1 The HTML5 jQuery Audio Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
a0297cab-8b6f-4e09-b552-4772c6f72c04
< 1.6.4
MEDIUM 6.1 The Elementor Addon Elements plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter … wordfence
a0247ba6-d193-4b7d-969d-0cd239c57faa
< 2.2.25
MEDIUM 6.1 The Biteship plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'biteship_error' and 'biteship… wordfence
← Prev 857 858 859 860 861 862 863 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top