πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 925 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5a92bc9b-1cc5-49b7-983c-a245b96d4167
< 5.4.1
MEDIUM 6.1 The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in al… wordfence
5a92945b-79ce-4bea-a1fc-0f03024f5f48 MEDIUM 6.1 The Optinferex Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜id’ parameter in all kn… wordfence
5a925c74-9f12-41e1-9443-d533b645c3f5
< 3.0.5
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Login With Ajax plugin before 3.0.4.1 for WordPress allows remote attack… wordfence
5a9000e3-a313-48f7-88cd-3041c8da8288
< 2.17
MEDIUM 6.1 The Post Duplicator plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.16 du… wordfence
5a85e1e9-ef40-40f6-a652-17acf0a2d33d
< 1.8.1
MEDIUM 6.1 The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
5a679863-3c22-4d34-9994-1f8ec121ad86
< 3.4.2.5
MEDIUM 6.1 The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Re… wordfence
5a616de7-ab81-4da9-8da6-7660b0b4c7cd
< 1.4.7
MEDIUM 6.1 The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site… wordfence
5a614ce5-faa4-4b27-84bd-f15f8652d477 MEDIUM 6.1 The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p' GET parameter… wordfence
5a5d7609-4d6a-4870-9e79-1f42ca22114d
< 2.6
MEDIUM 6.1 The Web Accessibility By accessiBe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up t… wordfence
5a595e05-c017-4f6a-995d-a6226c5a19b1 MEDIUM 6.1 The Mins To Read plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
5a52af45-30a6-4dea-b6ce-7d2e8af1910c
< 10.6.7
MEDIUM 6.1 The Wp EMember plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name fields in all versions up … wordfence
5a45bdc8-a181-43b2-ad82-abaf3ded1ef8 MEDIUM 6.1 The MultiParcels Shipping For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versio… wordfence
5a37c3d8-6496-4ca9-b145-920386deb812
< 7.9.4
MEDIUM 6.1 The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
5a316c0a-452a-4205-b79b-8bd911016ab2
< 1.3.2.1
MEDIUM 6.1 The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'datef' parameter on the '… wordfence
5a1a727e-3b06-41ca-b684-f31d48f685c0
< 3.2.6
MEDIUM 6.1 The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow paramete… wordfence
5a0974a5-cfed-4d4d-ae91-f74d9cd531e7
< 0.9.4
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Frontend Uploader plugin before 0.9.4 for WordPress allows remote attack… wordfence
5a093bd0-f8c5-47f2-943a-d4ce2aa8e402
< 3.0.6
MEDIUM 6.1 The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
5a03e1c3-618c-41b3-b803-ceab9d428d12
< 1.6
MEDIUM 6.1 The BP Email Assign Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
59f6de7c-b154-4007-bb4b-ea25e6a261ad MEDIUM 6.1 The Tayori Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
59d5e083-ab0d-4046-bcfe-b725e9d0e7c1 MEDIUM 6.1 The Nimbata Call Tracking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
59cefa5d-f270-48e1-bb3e-98f710a055d8
< 2.0.3
MEDIUM 6.1 wordfence
59c40a86-ea1c-4015-ac47-2b7b91cc3519
< 1.2.17
MEDIUM 6.1 The wordpress vertical image slider plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versi… wordfence
59c3b1df-7f8d-47a7-af20-d85116644ccf MEDIUM 6.1 The Todo Custom Field plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
59be2283-1356-48aa-bbda-f796fd799330
< 1.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in phprack.php in the DMCA WaterMarker plugin before 1.1 for WordPress allows r… wordfence
59ada382-5559-49a5-84ea-69201d185829
< 2.1
MEDIUM 6.1 The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX ac… wordfence
← Prev 922 923 924 925 926 927 928 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top