🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 922 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5dbd29ba-c4e8-4a43-b17c-332807570309
< 1.04
MEDIUM 6.1 The Highlight Searched Terms in Results plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions… wordfence
5dabf766-b288-48c1-8e89-f910d7ecf8a8 MEDIUM 6.1 The Food Store – Online Food Delivery & Pickup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
5da82149-c827-4574-8269-b2b798edca59
< 1.1.2
MEDIUM 6.1 The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the… wordfence
5d9e0147-74ae-481a-bdc2-16bb3cdc10d7
< 1.3.0
MEDIUM 6.1 The Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider Name Section in … wordfence
5d9b819e-7c5f-46f5-a9c7-8ef124537f99 MEDIUM 6.1 The TTT Crop plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0 … wordfence
5d9aaf0f-b5e1-4d2d-9e0f-4b5a4430fa96 MEDIUM 6.1 The Business Template Blocks for WPBakery (Visual Composer) Page Builder plugin for WordPress is vulnerable to Reflected… wordfence
5d8cec6f-833b-4bb9-954e-a985a3c5067c MEDIUM 6.1 The LambertGroup - AllInOne - Banner with Playlist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
5d896366-a85d-49c9-9509-3f7454712474 MEDIUM 6.1 The Cloud Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ricerca’ parameter i… wordfence
5d7b33c5-ced5-4ce5-acc1-4c3d935f8749 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in post_alert.php in Alert Before Your Post plugin, possibly 0.1.1 and earlier,… wordfence
5d74ca27-7be9-4ab3-a6be-0c23b195a3cb
< 2.3.12
MEDIUM 6.1 The Smart Slider 2 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘type', 'gotopreset’… wordfence
5d6bebb7-375c-45b8-9b54-58c6dbc0bb70
< 1.4
MEDIUM 6.1 The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflec… wordfence
5d615acb-2960-4296-b212-0feaed2af8e2
< 5.9
MEDIUM 6.1 The Library Bookshelves plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
5d54788a-ebfd-4291-94f2-d220fbf9050a
< 1.1.14
MEDIUM 6.1 The Contact Form 7 Connector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' paramete… wordfence
5d4b8d86-929b-4a35-b438-1f2957a5f11d MEDIUM 6.1 The Flashfader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
5d4ab9fd-47ef-4668-91df-c3d715da5574 MEDIUM 6.1 The Rebrand Fluent Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
5d3029bb-74d0-4594-80c9-b7cb6c049216 MEDIUM 6.1 The Geo Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL path in all versions up to,… wordfence
5d2fff42-19a7-47a3-9f88-76e81d485199 MEDIUM 6.1 The AdSense Privacy Policy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
5d194bca-0373-4c50-aee6-966e1692f3bc MEDIUM 6.1 The WP微信机器人 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
5d14dfc0-13e2-41bb-b8f1-9a4919491cd2 MEDIUM 6.1 The WP Event Ticketing plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
5cf85717-179a-4539-b57d-fccd8d9dda58
< 2.3.2
MEDIUM 6.1 The Category Grid View Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ par… wordfence
5cf7075f-7209-49e6-acf9-6739b178d4dc
< 2.0.13
MEDIUM 6.1 The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on… wordfence
5ceb8f67-0c7a-4028-81b9-f2cdbcba1a80
< 2.1.6
MEDIUM 6.1 The LuckyWP Table of Contents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the attrs paramet… wordfence
5ce9dd21-3c89-4ddd-9022-f1edf1224e2d MEDIUM 6.1 The WordPress Mortgage Calculator Estatik plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an un… wordfence
5cd706cd-bca4-4269-831f-7314f9a1797c MEDIUM 6.1 The Sticky Radio Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
5cbbe2c5-2a5d-4d87-a0b5-07c3583311ec
< 4.1.1
MEDIUM 6.1 The Atarim plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.1.0 … wordfence
← Prev 919 920 921 922 923 924 925 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top