ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 908 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
746b9ecc-49c1-4f6e-9f86-4147c98fe325
< 3.2.3
MEDIUM 6.1 The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data para… wordfence
7448983b-47ad-4a71-84a8-ee1f96b3f6cb
< .47.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in bulletproof-security/admin/options.php in the BulletProof Security plugin be… wordfence
7438623e-690e-400c-a9ef-0a02eda0e494 MEDIUM 6.1 The Backlink Monitoring Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order' par… wordfence
742acb6b-a799-4bb8-b4dc-f7359e7fdd4e
< 4.5
MEDIUM 6.1 The iframe plugin before 4.5 for WordPress does not sanitize a URL. wordfence
741ad2f5-d5cf-44bc-ac4a-7894df77a3d1
< 2.0.4
MEDIUM 6.1 The Keep Backup Daily plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via any URL parameter in vers… wordfence
741764b3-b147-416f-85b9-5dca994b4f18 MEDIUM 6.1 The AI Responsive Gallery Album plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
74172fcb-7428-464a-89f1-f1f3af50e361
< 4.5.6
MEDIUM 6.1 The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘optio… wordfence
741582e9-e99a-4756-a817-d120135d77c9
< 1.0.0
MEDIUM 6.1 The Sleekplan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.2… wordfence
7412030e-94ec-40d2-8cbc-d5df9a7f1c5b MEDIUM 6.1 The Restrict User Registration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
741028c9-6021-4522-b7e5-b31f0c3a9f10
< 4.9.35.1
MEDIUM 6.1 cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has X… wordfence
73fe5da6-165d-454f-91d8-73d4cb90f5df MEDIUM 6.1 The Contact Form 7 – Paystack Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versi… wordfence
73fae3a0-6987-45bf-a20e-4ea9c6f73924
< 3.4.8.5
MEDIUM 6.1 The weblibrarian plugin before 3.4.8.5 for WordPress has XSS via front-end short codes. wordfence
73f7646f-f01f-4f57-836c-e0bd04764ba9 MEDIUM 6.1 The 1 Decembrie 1918 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
73de57bf-ca40-45f3-ab5c-021704436a23
< 1.1.6
MEDIUM 6.1 The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1.5.… wordfence
73d3f73f-5407-4acf-ac65-1f7eadbaa58f
< 1.9.3
MEDIUM 6.1 The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter befo… wordfence
73cbb65e-b4e3-4374-9916-9a3d1be5a014
< 6.4.9
MEDIUM 6.1 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site… wordfence
73af1648-5248-45e4-8663-79595a70528a MEDIUM 6.1 The Zorka – Wonderful Fashion WooCommerce Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
73aad911-531b-4118-9d39-27cbae75db01
< 1.1.24
MEDIUM 6.1 The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… wordfence
73a83f2b-835b-44cd-9d09-1b4fba3e9c8b
< 1.0.5
MEDIUM 6.1 The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1… wordfence
73a15b12-20d5-4448-b69c-9a577ff907b9
< 3.52
MEDIUM 6.1 The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includ… wordfence
73913fc5-aee4-4613-9bd6-76e091227c2c
< 4.8.1
MEDIUM 6.1 The Verge3D plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.8.0… wordfence
7356a030-14c8-4fcb-b5a2-cf23d8a8bc7f MEDIUM 6.1 The List of Posts from each Category plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
734b6ae0-b2f6-4bad-a6d3-bef48fd8cdd0
< 5.5.2
MEDIUM 6.1 The Events Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.5.1 du… wordfence
73472066-8e5c-46a4-906d-f459a2ebf40d
< 3.0
MEDIUM 6.1 The WP Voting Contest WordPress plugin before 3.0 does not sanitise and escape the post_id parameter before outputting i… wordfence
7346eeba-904b-4cf9-9d10-33a33120aea4
< 3.10.2
MEDIUM 6.1 Reflected Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern… wordfence
← Prev 905 906 907 908 909 910 911 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top