🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 915 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
65647429-8c76-4538-9725-91fda7fd7d4e MEDIUM 6.1 The Better User Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
65644477-263d-493d-99df-80fc558aad51
< 1.0.5
MEDIUM 6.1 The Cleanup – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to Reflected Cross-S… wordfence
655729e1-9002-4ca5-be08-9fb601fb53ad MEDIUM 6.1 The Magic Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
65402225-99ba-49ff-807b-b8e4cf474ffb
< 1.5.68
MEDIUM 6.1 The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues v… wordfence
653fbe5d-3388-4227-8a0a-46764b6be4d2
< 2.1.16
MEDIUM 6.1 The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attri… wordfence
65329e2c-0ce2-4033-93a8-ba52ae3774c1 MEDIUM 6.1 The Audio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.6.1 d… wordfence
651df16c-2472-4124-90a3-69b98e478ed3
< 3.37.30
MEDIUM 6.1 The WP Fusion Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the startdate parameter found in… wordfence
651572c7-83e0-4651-aa43-9177fbf9d91e MEDIUM 6.1 The LeanPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0… wordfence
650dfc4c-d851-481c-af8f-4dfe1e128a1d
< 2.0.4
MEDIUM 6.1 The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an … wordfence
650dbbaa-4348-42a6-973c-487f53430955
< 3.3.40
MEDIUM 6.1 The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back i… wordfence
64e14944-db83-413f-82a3-cda594398c7e
< 1.34.1
MEDIUM 6.1 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflecte… wordfence
64de1220-52f5-46a9-b8ba-cf808d5d2e29
< 4.9.9
MEDIUM 6.1 The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
64d2174e-ee69-4e71-b8cb-ff7a1ba0f52f
< 3.9.24
MEDIUM 6.1 The Locatoraid Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lpr-search' p… wordfence
64cf73fa-cdb9-4703-869e-343ee6f8178e
< 1.2.9
MEDIUM 6.1 The TinyChat Room Spy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'room' parameter in v… wordfence
64ccf609-5cdf-4f05-ad83-4fb7aa475ba5
< 1.2.8
MEDIUM 6.1 iThemes Mobile before 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg(). wordfence
64abe00c-05b7-4661-b560-bae3957ad3e2 MEDIUM 6.1 The Bulk Creator WordPress plugin through 1.0.1 does not sanitize and escape the post_type parameter before outputting i… wordfence
64aa76c3-a70a-4939-ad46-b2e67a556124
< 2.7.10
MEDIUM 6.1 The Video Share VOD plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
64aa45bd-7bf8-4fe9-85e7-ace226e09f34
< 3.1.15
MEDIUM 6.1 WebAppick WooCommerce Product Feed 3.1.14 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to … wordfence
64a7a4db-8b28-4085-91b0-4ea5343c5643
< 1.1
MEDIUM 6.1 The Import WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'alertmsg’ paramet… wordfence
64827b61-42ea-454a-b41d-85ce8d6ad866
< 3.0.0.5
MEDIUM 6.1 The LoginWP (Formerly Peter's Login Redirect) WordPress plugin before 3.0.0.5 does not sanitise and escape the rul_login… wordfence
64729dfb-adfe-4eb8-ad3e-03a5784f19a1 MEDIUM 6.1 The Privacy Policy Genius plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
646e3a57-92e1-4502-a0dd-8921e99cfe2d
< 3.0.3
MEDIUM 6.1 The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote atta… wordfence
646ba700-28d5-455f-88de-2864ef8f202c
< 1.4.18
MEDIUM 6.1 The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
646af494-5348-484a-80d8-0f9a11ed310e
< 5.8.2
MEDIUM 6.1 The DeBounce Email Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
645ec67e-f0a3-4273-970c-2073d9a80b4f MEDIUM 6.1 The WP Query Creator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
← Prev 912 913 914 915 916 917 918 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top