🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 927 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
587e28ea-b3f4-4e40-a7d2-c6a01ac905bf MEDIUM 6.1 The Video Url plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in all version… wordfence
587a2f1a-7f24-4ab2-b15f-0a022af3861e MEDIUM 6.1 The WPLMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.9.8… wordfence
5872a69d-3314-4900-8f7b-bcbd8787a9fe MEDIUM 6.1 The Fancy Cats for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catSlug’ and ‘showAllText’… wordfence
586c8952-a427-47f8-8d2d-117e527b0f74
< 2.1
MEDIUM 6.1 The Dropdown and scrollable Text WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the content parame… wordfence
584d4517-1152-42fa-9ea9-a9e9ed8996fa
< 3.1.11
MEDIUM 6.1 The BlockMeister – Block Pattern Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to t… wordfence
58410382-8820-49e2-8dfd-87937287b8d1 MEDIUM 6.1 The S3 Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media' parameter in version… wordfence
582a536c-950e-424b-80a7-83608d220b87
< 2.72
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the GRAND FlAGallery plugin before 2.72 for WordPress … wordfence
5817384f-1626-4393-a879-931fe7e551f1 MEDIUM 6.1 The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' par… wordfence
5811e36d-9457-4460-af92-046ddef41114
< 24.0303
MEDIUM 6.1 The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
5805b1f1-34e7-49d5-93dd-748113b6093b
< 9.8.6
MEDIUM 6.1 The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' pa… wordfence
57ff8e0b-92cd-49e1-9db7-91c970282e21 MEDIUM 6.1 The Side Slide Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
57f77795-57bc-4448-baf1-b9da6b0c61b7 MEDIUM 6.1 The CJ Custom Content plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
57f70dac-9439-4f70-8a73-6ffefcaefa22 MEDIUM 6.1 The ECT Product Carousel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
57e724ac-8e7d-45ec-9f41-4303ea6c5d30 MEDIUM 6.1 An XSS issue was discovered in the slickquiz plugin through 1.3.7.1 for WordPress. The save_quiz_score functionality ava… wordfence
57dc6ca5-6e6b-4364-9b82-31fe108fece8
< 2.7.38
MEDIUM 6.1 The Ad Inserter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2… wordfence
57d3506c-8db8-4e1b-9587-7f2bdb632890
< 1.2.1
MEDIUM 6.1 The Conditional Menus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'current_page' and '… wordfence
57d2ac19-812a-4a64-815b-bc3fffe8af26 MEDIUM 6.1 The Yet Another bol.com Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SER… wordfence
57be47e2-9aac-42bd-af6a-5060d2f86449
< 1.4.7
MEDIUM 6.1 The User Activity Log plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "$_SERVER['QUERY_STRI… wordfence
57a962c9-f909-4410-a244-82e557ef1695
< 1.6.4
MEDIUM 6.1 The Enzy theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to 1.6.4 (exclusive) due… wordfence
57a78696-5892-4621-992f-5e4a7d8fa965
< 3.6.18
MEDIUM 6.1 The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in… wordfence
57a6eaad-920a-487c-9e22-99caf0262b05 MEDIUM 6.1 The Mapbox for WP Advanced plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
57a68d4a-4857-4631-8863-6ff847490ef5
< 1.4.4.3
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in test.php in the WP Social Invitations plugin before 1.4.4.3 for WordPress al… wordfence
578d8ca7-7042-493d-92b4-63241b4bdfca
< 3.10.1
MEDIUM 6.1 The Profile Builder Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in… wordfence
578b17d4-16cf-449a-9d99-cd9a0f7a8418
< 0.5
MEDIUM 6.1 The Database Sync plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in ve… wordfence
577cf51e-3fcb-456c-9068-17fff4a71e94 MEDIUM 6.1 The Map Multi Marker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
← Prev 924 925 926 927 928 929 930 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top