πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 903 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
72505ab0-8545-4735-af15-e8794d0ac9c9
< 4.0.6
MEDIUM 6.1 The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages. wordfence
724dead7-0e4a-420d-a5a3-fca578451211
< 3.2.0
MEDIUM 6.1 The Simple Social Media Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions u… wordfence
724d8382-cef3-4584-a255-c2ecc7c986b3
< 4.9.9.3
MEDIUM 6.1 The brooklyn theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all version… wordfence
724a7579-74c6-46b2-b1b4-a92e980aaa83
< 3.11.2
MEDIUM 6.1 The Custom 404 Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'c4pmessageType' and 'c4… wordfence
72383bd3-82b4-4aea-9a1c-277ad06e2500
< 5.1.2
MEDIUM 6.1 The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg with… wordfence
722d3a5e-40dc-4153-b8ce-4a94ae391896
< 2.4.4
MEDIUM 6.1 The CityBook plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'distance', 'address_lat', and… wordfence
72256ac2-72a7-4c3c-a892-1f1795671c5d
< 2.2.2
MEDIUM 6.1 The Vimeotheque plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the view' and 'page' parameters… wordfence
721b2e7d-59be-40c9-b5a9-dec679c3e99c MEDIUM 6.1 The Directory Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
72154a2d-05aa-4a13-89c5-c9bfdf5b2e7e MEDIUM 6.1 The CG Button plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0… wordfence
720d1d50-06ae-4b47-ac64-115c00d81223
< 4.1.1
MEDIUM 6.1 The Estatik Real Estate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad… wordfence
7203b9df-bde1-47cd-9a2c-bc8f19cd64f8
< 3.5.5
MEDIUM 6.1 The SHOUT - HTML5 Radio Player With Ads - ShoutCast and IceCast Support plugin for WordPress is vulnerable to Reflected … wordfence
7202c0f7-cde7-4588-95f4-367d91f2eb67
< 10.16
MEDIUM 6.1 The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
71fe2687-0dc9-4c56-91a4-447420818cca
< 3.7.33
MEDIUM 6.1 In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user passwo… wordfence
71e26ec2-4dd2-4762-a7dc-6ed2755eb6ba
< 4.9.9
MEDIUM 6.1 The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
71cf73a1-8518-40ac-b105-a87142d91a91
< 1.3.1
MEDIUM 6.1 The Simple Certain Time to Show Content plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all vers… wordfence
71bf0ae5-7c32-42ac-a9bc-96cb1269a458 MEDIUM 6.1 The kioskprox plugin for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and outp… wordfence
71aeca29-a9bd-42c0-8150-814b79e931fa
< 1.2.1
MEDIUM 6.1 The Cross-Site Scripting plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.… wordfence
718d12fe-31e4-4fa1-ba9a-8626df8ddbfe
< 1.11.30
MEDIUM 6.1 The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mepr_screenname' and 'mepr… wordfence
71859023-c64a-4d77-8505-33fe4fae2475
< 3.1.5
MEDIUM 6.1 The Bold pagos en linea plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
716d4f0b-939c-42c2-bfb8-dc39df79bdbc MEDIUM 6.1 The WP Custom Google Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
714d7811-0425-4833-a7b2-a408799181e4 MEDIUM 6.1 The Who Hit The Page – Hit Counter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown… wordfence
7141edc6-8b34-4624-8264-9ca1696ccdbf MEDIUM 6.1 The Stray Random Quotes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'qo' parameter in a… wordfence
713aff2e-2e61-400d-9454-a61fad5e374b
< 1.2
MEDIUM 6.1 The Dynamic URL SEO plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.0 due… wordfence
712ffe0a-45a5-41c7-a2b9-e88fb381a684
< 2.0.0
MEDIUM 6.1 The Bulk Delete Users by Email plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'de-text' pa… wordfence
712d2d8b-2103-4262-807e-bb26cabb771c
< 14.0
MEDIUM 6.1 The Wonder Slider Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in … wordfence
← Prev 900 901 902 903 904 905 906 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top