🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 902 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
73aad911-531b-4118-9d39-27cbae75db01
< 1.1.24
MEDIUM 6.1 The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… wordfence
73a83f2b-835b-44cd-9d09-1b4fba3e9c8b
< 1.0.5
MEDIUM 6.1 The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1… wordfence
73a15b12-20d5-4448-b69c-9a577ff907b9
< 3.52
MEDIUM 6.1 The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includ… wordfence
73913fc5-aee4-4613-9bd6-76e091227c2c
< 4.8.1
MEDIUM 6.1 The Verge3D plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.8.0… wordfence
7356a030-14c8-4fcb-b5a2-cf23d8a8bc7f MEDIUM 6.1 The List of Posts from each Category plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
734b6ae0-b2f6-4bad-a6d3-bef48fd8cdd0
< 5.5.2
MEDIUM 6.1 The Events Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.5.1 du… wordfence
73472066-8e5c-46a4-906d-f459a2ebf40d
< 3.0
MEDIUM 6.1 The WP Voting Contest WordPress plugin before 3.0 does not sanitise and escape the post_id parameter before outputting i… wordfence
7346eeba-904b-4cf9-9d10-33a33120aea4
< 3.10.2
MEDIUM 6.1 Reflected Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern… wordfence
73442cf9-615a-47a0-860e-fb8263ae65ee
< 1.3.2
MEDIUM 6.1 The Custom Fields Search by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘… wordfence
7332c21a-3501-4066-b7b7-34914a228d8f
< 2.2.6
MEDIUM 6.1 The SmartEmailing.cz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'se-lists-updated' par… wordfence
7327f439-0088-4ad8-898a-30740fc62d6e
< 2.1.6
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Pixiv Custom theme before 2.1.6 for WordPress allows remote attackers to… wordfence
730dac2b-edc2-4bfc-a1c5-ffeba71308ad
< 1.0.5
MEDIUM 6.1 The Popular Posts by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘categor… wordfence
72f5213a-4a1e-4e71-b67a-09a9bb527bfa MEDIUM 6.1 The Broken Links Remover plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
72f3416a-4d5e-4b95-8f83-7b9440f9e9df
< 1.4.4
MEDIUM 6.1 The Page Parts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg w… wordfence
72e7dbe0-0e48-4511-9e35-77af7d3d13e5
< 4.4.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Contact Form Clean and Simple (clean-and-simple-contact-form-by-meg-nich… wordfence
72d33132-aba7-4e97-90c6-359298b1c06e
< 6.62
MEDIUM 6.1 The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to… wordfence
72c5fd31-f457-494a-a160-1f64366e3e63 MEDIUM 6.1 The Pondol Form to Mail plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the 'itemid' parameter … wordfence
72bf7aa9-9b3c-4229-b5ba-989303379feb MEDIUM 6.1 The Random Quotes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
72a56589-9dc0-47a7-bb68-e31f84a639ee MEDIUM 6.1 The Advanced Advertising System plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including… wordfence
72a0df23-38cd-4926-9099-8eb652e05a15
< 2.3.8
MEDIUM 6.1 The Variation Swatches for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the last… wordfence
728f9fe0-2a23-4f99-af30-386ce1c1f44f MEDIUM 6.1 The LJ Custom Menu Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
72880e44-b0e0-47f4-82f0-c36c81091ba8 MEDIUM 6.1 The Easy PayPal Gift Certificate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
72702870-8a1a-446b-8f9f-bd435e9257f2 MEDIUM 6.1 The WP-OAuth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error_description' parameter … wordfence
72564bc8-48b2-4fd2-aeb9-dc0bfdcf93d1
< 7.2
MEDIUM 6.1 The ARforms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.1.2… wordfence
7255e9b0-d56c-4cd6-b27b-ffb6e1a988cc MEDIUM 6.1 The R3W InstaFeed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
← Prev 899 900 901 902 903 904 905 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top