ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 901 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
74db4d3a-ee3f-460a-b880-f61a8e33ea57
< 1.7.8
MEDIUM 6.1 The myCred WordPress plugin before 1.7.8 does not sanitise and escape the user parameter before outputting it back in th… wordfence
74cc9d91-5b6a-48fc-8bd1-01100b45ffdb MEDIUM 6.1 The Custom Post Type Relations WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the cptr[name] param… wordfence
74c1bc1d-27f1-4953-8ebd-9396fce0f834
< 4.3.7
MEDIUM 6.1 The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress … wordfence
74a33813-ca5a-4cf4-9d36-b71ca76b8915
< 3.0.72
MEDIUM 6.1 The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and inclu… wordfence
748d817d-2a47-4426-b166-746ee89d9e61 MEDIUM 6.1 The SVG Captcha plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
748101c3-0a47-4a3d-b2c1-e05d0919432b MEDIUM 6.1 The CJ Change Howdy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3… wordfence
74732912-979a-41e6-95de-e34b1847f8d3 MEDIUM 6.1 The RSS Filter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
746bf178-5e1b-4f1a-8072-d0c1be005f88 MEDIUM 6.1 The Post Hits Counter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
746b9ecc-49c1-4f6e-9f86-4147c98fe325
< 3.2.3
MEDIUM 6.1 The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data para… wordfence
7448983b-47ad-4a71-84a8-ee1f96b3f6cb
< .47.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in bulletproof-security/admin/options.php in the BulletProof Security plugin be… wordfence
7438623e-690e-400c-a9ef-0a02eda0e494 MEDIUM 6.1 The Backlink Monitoring Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order' par… wordfence
742acb6b-a799-4bb8-b4dc-f7359e7fdd4e
< 4.5
MEDIUM 6.1 The iframe plugin before 4.5 for WordPress does not sanitize a URL. wordfence
741ad2f5-d5cf-44bc-ac4a-7894df77a3d1
< 2.0.4
MEDIUM 6.1 The Keep Backup Daily plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via any URL parameter in vers… wordfence
741764b3-b147-416f-85b9-5dca994b4f18 MEDIUM 6.1 The AI Responsive Gallery Album plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
74172fcb-7428-464a-89f1-f1f3af50e361
< 4.5.6
MEDIUM 6.1 The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘optio… wordfence
741582e9-e99a-4756-a817-d120135d77c9
< 1.0.0
MEDIUM 6.1 The Sleekplan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.2… wordfence
7412030e-94ec-40d2-8cbc-d5df9a7f1c5b MEDIUM 6.1 The Restrict User Registration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
741028c9-6021-4522-b7e5-b31f0c3a9f10
< 4.9.35.1
MEDIUM 6.1 cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has X… wordfence
73fe5da6-165d-454f-91d8-73d4cb90f5df MEDIUM 6.1 The Contact Form 7 – Paystack Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versi… wordfence
73fae3a0-6987-45bf-a20e-4ea9c6f73924
< 3.4.8.5
MEDIUM 6.1 The weblibrarian plugin before 3.4.8.5 for WordPress has XSS via front-end short codes. wordfence
73f7646f-f01f-4f57-836c-e0bd04764ba9 MEDIUM 6.1 The 1 Decembrie 1918 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
73de57bf-ca40-45f3-ab5c-021704436a23
< 1.1.6
MEDIUM 6.1 The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1.5.… wordfence
73d3f73f-5407-4acf-ac65-1f7eadbaa58f
< 1.9.3
MEDIUM 6.1 The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter befo… wordfence
73cbb65e-b4e3-4374-9916-9a3d1be5a014
< 6.4.9
MEDIUM 6.1 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site… wordfence
73af1648-5248-45e4-8663-79595a70528a MEDIUM 6.1 The Zorka – Wonderful Fashion WooCommerce Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
← Prev 898 899 900 901 902 903 904 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top