ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 898 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7849addf-cdee-4de2-9b6c-bb1c92a472fd
< 5.20.1
MEDIUM 6.1 The Event Tickets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
7848e904-b521-479b-bf7e-d695ad0163b0
< 2.6.6
MEDIUM 6.1 The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an a… wordfence
78393d56-5e83-4eac-bee7-a194aaaa8f5e MEDIUM 6.1 The Category Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
78391643-6625-4f5b-a08d-3d8462292a1e MEDIUM 6.1 The iContact for Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
78376368-4883-48ce-aad0-e1d5a993cd74
< 9.7.2
MEDIUM 6.1 Authenticated (admin or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in Biplob Adhikari's Image … wordfence
7831b324-7016-4a5e-85bb-89de773cde0e MEDIUM 6.1 The The Loops plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
782e30a7-6813-47b4-b447-d5f03dcb9dc4
< 4.1.6
MEDIUM 6.1 The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it bac… wordfence
7821b17a-7da7-434f-8e3f-540e7d7cf6bb
< 3.9.48
MEDIUM 6.1 The Locatoraid Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST keys in all… wordfence
7817f343-1ed6-4b76-afbe-1054de892422
< 6.8.7
MEDIUM 6.1 The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sSh… wordfence
7809697d-367a-4051-9865-440ba8ce7ad5
< 3.0.9
MEDIUM 6.1 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
77ff6195-e2e6-49bd-a96e-d2f60b309368
< 2.14.3
MEDIUM 6.1 The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it b… wordfence
77fdfb42-6540-43be-be5c-63dd6e1a34d7
< 3.8.9
MEDIUM 6.1 The Headway theme before 3.8.9 for WordPress has XSS via the license key field. wordfence
77fd0714-ae9d-4136-beed-7f37b1266dc9
< 1.4.3
MEDIUM 6.1 The iPages Flipbook plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in… wordfence
77f3db0c-d575-48a8-872a-a64fd77486de
< 2.0.13
MEDIUM 6.1 The WooCommerce plugin for WordPress is vulnerable to Self-Reflected Cross-Site Scripting in versions up to, and includi… wordfence
77d66e98-9987-430d-8866-496debe8f65e
< 3.2.2
MEDIUM 6.1 The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
77cf3e7c-bcb5-421d-a537-a0d28c36cd05 MEDIUM 6.1 The price-calc plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.… wordfence
77cc3871-664b-404c-b06c-b757374a777a
< 1.4.23.1
MEDIUM 6.1 The Shipment Tracker for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all version… wordfence
77b7cf5d-2dad-4a4f-ae48-f1ab86065c2d
< 4.3.0
MEDIUM 6.1 The Careerfy theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.2.0… wordfence
77ab3a4b-da39-454e-b223-56a36a7c9447 MEDIUM 6.1 The MDR Webmaster Tools plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
7794f043-0e0b-4ff3-b2dd-1caff8d7168d
< 1.7.1
MEDIUM 6.1 The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outpu… wordfence
778aa2be-ffcb-4d28-9efe-c29c8d5391bd MEDIUM 6.1 The HDW Player Plugin (Video Player & Video Gallery) plugin for WordPress is vulnerable to Cross-Site Scripting in versi… wordfence
77838bf8-7809-4dd6-87f1-a9bda40275a6
< 2.6.4
MEDIUM 6.1 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO plugin for WordPress is vulnerable to… wordfence
777e2e60-46c3-496c-8263-f2e253014ba5
< 1.5.4
MEDIUM 6.1 The Get Use APIs – JSON Content Importer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … wordfence
776a0059-9e9a-454a-a325-2e3a0e133000 MEDIUM 6.1 The SpiderVPlayer for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s_v_player_id’ parameter in… wordfence
7769f3d4-041d-445f-a5fc-d5bc9e45ed58
< 1.5.4.1
MEDIUM 6.1 The WPCOM Member plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'login_redirect' parameter… wordfence
← Prev 895 896 897 898 899 900 901 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top