πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 890 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
81a3460e-f2c8-422f-9256-3aef24afb42b
< 1.3.8.5
MEDIUM 6.1 The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not sanitise and escape POSted parameters sen… wordfence
819f93ae-cfbd-4ba5-979f-18adc7b9c8fe
< 7.1.8
MEDIUM 6.1 The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
818c9ddc-be95-4997-8041-cf856a964657
< 2.37.4
MEDIUM 6.1 The PowerPack for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
8173596d-a127-4dc1-a72a-640381536c67
< 3.1.31
MEDIUM 6.1 The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape t… wordfence
816956d1-8a76-44ff-841a-e609c6e51af3 MEDIUM 6.1 The Eli's WordCents adSense Widget with Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting i… wordfence
816573b7-e720-4470-a929-a6cad0d73dc8
< 1.2
MEDIUM 6.1 The Easy restaurant menu manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and inclu… wordfence
815054e2-c575-439a-9a66-fce251b4da80
< 18.2
MEDIUM 6.1 The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' … wordfence
81437db2-252e-4031-884e-34112bc7b179
< 2.3.1
MEDIUM 6.1 The Top 10 – Popular posts plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the 'pa… wordfence
813f57ca-9c6a-48bc-a013-428cc93ff24d MEDIUM 6.1 The Auto Login After Registration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
8139f512-7bc9-45ae-83d7-bf496e1ad56d
< 2.3.3
MEDIUM 6.1 The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parame… wordfence
8129bc3a-41c9-4a1e-8e04-55e23bb8d46d
< 4.2.0
MEDIUM 6.1 The Smoove connector for Elementor forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the… wordfence
81108abb-69e5-4571-8209-484b4b0f5617
< 5.9.0
MEDIUM 6.1 The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an a… wordfence
810c641b-e9e0-462c-96ef-008c083208a0
< 2.3.5
MEDIUM 6.1 The Simplr Registration Form Plus+ plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in ver… wordfence
810a999d-c5d5-4004-9399-bb5d64734266
< 1.6.4
MEDIUM 6.1 The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin plugin for WordPress is vulnerable to Reflect… wordfence
81070529-b269-44b0-8f21-b08add63a099 MEDIUM 6.1 The AuthorSure plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.… wordfence
81062f13-98ed-4ba7-8725-35406ac71568
< 0.3
MEDIUM 6.1 The ThinkIT WP Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜ID’ parame… wordfence
80fce3ef-ab77-40e1-a98f-bb0c3f9924d6
< 3.4.7
MEDIUM 6.1 The Ali2Woo Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.… wordfence
80fb6ac9-29af-4a11-ad2f-52cc1bfda6b3
< 2.0
MEDIUM 6.1 The Backend Localization plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_quer… wordfence
80e2f799-2cd7-414f-9701-2269eeecf22a MEDIUM 6.1 The MemeOne plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.5… wordfence
80d113aa-7401-4b58-a755-f64146d9fb08
< 4.0.31
MEDIUM 6.1 The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress … wordfence
80c90bc0-ca24-4c7f-93b9-a9d0804ee459
< 3.1.78
MEDIUM 6.1 The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Reflected … wordfence
80b6f2e6-1f06-4ead-8c31-fc4fffe8323b
< 1.1.5.3
MEDIUM 6.1 The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'offset' and 'type' parameters i… wordfence
80b31295-474e-4375-b566-c628e869da10
< 9.1.2
MEDIUM 6.1 A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Tick… wordfence
80a627a5-6b76-4525-a76a-ac96986bd21b MEDIUM 6.1 The Animal Captcha plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜num’ parameter in v… wordfence
80a5fac0-9f85-4de1-9c15-51e9bd65e47b MEDIUM 6.1 The UltraLight theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2… wordfence
← Prev 887 888 889 890 891 892 893 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top