πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 926 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
59971f3d-2f98-44fd-a105-621a315721ae
< 15.9
MEDIUM 6.1 The WP Symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?… wordfence
5992161c-65ad-4601-8ebc-b53470f49c1c
< 3.1.3
MEDIUM 6.1 The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Reflected Cross-Site Sc… wordfence
598529d2-16c7-4bbd-9321-aa338c94eb36 MEDIUM 6.1 The Post Like Dislike plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']… wordfence
597f06ac-f9c7-4dcb-bb72-15ed7e9d8ac6
< 1.23.4
MEDIUM 6.1 The UpdraftPlus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.23.… wordfence
597786ce-58eb-4e96-a80e-bad3e75787fa
< 3.2.8
MEDIUM 6.1 The Payment gateway per Product for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via… wordfence
59707c64-a34c-45bc-bbbe-d447fe2ca6ab
< 1.3.2
MEDIUM 6.1 The Loggedin – Limit Active Logins plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use… wordfence
5954369b-ff1b-40ff-a20d-1b2b237a6f42 MEDIUM 6.1 The WP-SpamFree Anti-Spam plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wordpress_commen… wordfence
594eb248-7aa3-4af9-b96c-6003a1899ae0 MEDIUM 6.1 The My Post Order plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
594431b7-9bc7-4e86-bc20-311fdab657b6
< 3.8.1
MEDIUM 6.1 The JetEngine plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.8… wordfence
59391c74-0287-4375-8215-388cc918ea3c MEDIUM 6.1 The Cerato theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.18 … wordfence
59390594-494d-47ed-8550-8fe33dd53a18 MEDIUM 6.1 The SMu Manual DoFollow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
5934d1c8-1553-4908-aaab-89d2189eb4cd
< 7.4.3
MEDIUM 6.1 The WP Shortcodes Plugin β€” Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… wordfence
592ee7b9-7016-4df3-9218-6f7aebf80503
< 2.1.8
MEDIUM 6.1 The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use… wordfence
5909513d-8877-40ff-bee9-d565141b7ed2 MEDIUM 6.1 The nsc theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, a… wordfence
58f35c9f-7df6-4439-9c92-cf9a11d609e2 MEDIUM 6.1 The Post And Page Reactions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
58f041ec-179d-41d7-9fb9-73045f0c2107 MEDIUM 6.1 The WP-Easy Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
58e8befa-bc8d-4731-be2c-ccf613b39fdd
< 1.19.6
MEDIUM 6.1 The Shipping with Venipak for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '… wordfence
58e3cf2c-aaca-40f2-b4d4-adcab550ba56
< 30.1
MEDIUM 6.1 The Hostiko - Hosting WordPress & WHMCS Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all… wordfence
58d55ee8-ecd9-4444-a67b-4a62d235e9d3 MEDIUM 6.1 The WpZon – Amazon Affiliate Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
58c63799-7d6a-417d-9992-4ab425ae1f1e
< 1.16.69
MEDIUM 6.1 The UpdraftPlus WordPress Backup Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'up… wordfence
58c30b06-3d31-4489-a068-d447042eea58
< 4.2
MEDIUM 6.1 The "Zoner - Real Estate WordPress Theme" theme for WordPress is vulnerable to Cross-Site Scripting via the 'Address' fi… wordfence
58afd7cf-1d17-41e7-9bd3-9485bd733c6b
< 1.6.7
MEDIUM 6.1 The Yobazar theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 1.6.7 due to insuffici… wordfence
58aea6df-679d-4dd9-adfe-f73128d29187 MEDIUM 6.1 The Scroll UP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
588becbc-19a8-40bb-938a-b33b9c6d0513 MEDIUM 6.1 The FeedWordPress Advanced Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up t… wordfence
587eff5c-e551-4660-a1d4-11b9f1788f7d MEDIUM 6.1 The WP Donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.… wordfence
← Prev 923 924 925 926 927 928 929 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top