πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 923 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5cbbcc3f-b51b-4336-ab92-c6dca4c1510a MEDIUM 6.1 The HTTP to HTTPS link changer by Eyga.net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… wordfence
5c921300-88ef-43b8-959e-2bc490cf303f MEDIUM 6.1 The Mobile Site Redirect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
5c8b91c7-c5e9-4d39-a9ea-ed16d26031a4 MEDIUM 6.1 The Simple Responsive Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
5c830689-70bd-42cc-a385-fe8552f342a0
< 1.4.2
MEDIUM 6.1 wordfence
5c4f381f-aa03-46f9-aa27-daac4eed58c8 MEDIUM 6.1 The Simple Archive Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
5c402fcf-0c02-4a5e-89a9-8a1ddaa630d0
< 1.2.6
MEDIUM 6.1 The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?pag… wordfence
5c1d671c-017e-454b-8aa3-86f6d396b437 MEDIUM 6.1 The Widgets Controller plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1 … wordfence
5c18a9b8-5041-4451-a3cc-91952c234d9c
< 0.8.1
MEDIUM 6.1 The Cornerstone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
5c17b388-1f9a-473f-a71b-a3f72bdf301b MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in js/button-snapapp.php in the SnapApp plugin 1.5 and earlier for W… wordfence
5c17678e-6598-4e80-b121-beae822b9f81 MEDIUM 6.1 The Sermon'e – Sermons Online plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
5c164adc-7652-4076-b702-2dba38506fb3 MEDIUM 6.1 The Flickr Photostream plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
5c1464ab-217e-4c66-94f8-49376755dba7
< 2.7.17
MEDIUM 6.1 The WPFunnels plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the order_id parameter in version… wordfence
5c0e8e63-2603-4ee4-88f5-e132f9bc7fae
< 2.4.7
MEDIUM 6.1 The Razorpay Payment Button Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o… wordfence
5be3389e-f5cd-4462-b982-76e66203515b
< 3.0.0
MEDIUM 6.1 The WP w3all phpBB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
5be1cfcf-26f1-47d8-a48c-d9f385eb031a
< 2.0.8
MEDIUM 6.1 The Splash Sync plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wit… wordfence
5bdd515c-6b52-467c-9446-6ae9b3b75e50 MEDIUM 6.1 The Zingaya Click-to-Call plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email', 'first_n… wordfence
5bcfe315-2db1-4f6c-9635-a7fdf5404adf
< 1.13.3
MEDIUM 6.1 The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use … wordfence
5bcd9404-ff96-409f-a69d-3d744dfc940e MEDIUM 6.1 The Vignette Ads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
5badcfc6-aaff-4c8e-8649-98d71d7a47ec MEDIUM 6.1 The Music Request Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
5b989e3e-bfa7-47f5-83ba-24f47034e143
< 12.40
MEDIUM 6.1 The DZS Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
5b96e5ff-804c-41b6-ae34-5184a704b38e
< 6.4.0
MEDIUM 6.1 The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER["REQUEST_URI… wordfence
5b930316-7a2f-4539-8599-360751d49cde MEDIUM 6.1 The Smart Email Alerts WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the api_key in the ~/views/s… wordfence
5b909e12-8ed0-4348-adff-320d782abe75 MEDIUM 6.1 The Private Messages for UserPro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… wordfence
5b79b5ae-7ce5-4065-8d7c-487df6752bc7 MEDIUM 6.1 The Woocommerce check pincode/zipcode for shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… wordfence
5b768300-08c7-43cb-b6b2-579172dfc88e
< 2.0.5
MEDIUM 6.1 The Tag Groups is the Advanced Way to Display Your Taxonomy Terms plugin for WordPress is vulnerable to Reflected Cross-… wordfence
← Prev 920 921 922 923 924 925 926 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top