🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 928 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
577b4738-fa58-44b2-a8e7-ef59925f26a1
< 3.0.6
MEDIUM 6.1 The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including 3.0.5.… wordfence
57789905-1e08-41c5-bfda-b1d6d33de4c0 MEDIUM 6.1 The Clickbank WordPress Plugin (Storefront) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers… wordfence
577095f7-955f-46ab-ae5e-635fb4c65cbe
< 8.8.5
MEDIUM 6.1 The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via order attribution cookies in ve… wordfence
575e1255-14f5-449e-a6ee-64d203800853 MEDIUM 6.1 The Links/Problem Reporter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
5749a4e1-e7f3-4887-bf8c-49ffc095d0ee MEDIUM 6.1 The gAppointments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
5748d40a-e790-4a61-ab6a-a8750535c5bd MEDIUM 6.1 The NextGEN Gallery Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
574686c7-3ae3-48b4-8bea-4f96c7a6827f MEDIUM 6.1 The Okay Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
573dd1ea-1f2c-4a0b-9496-82d7b65c8db2
< 2.7.12
MEDIUM 6.1 The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputtin… wordfence
573b503e-7388-4e0d-a620-b87016028d79
< 2.0.1
MEDIUM 6.1 The XV Random Quotes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
5734bd3b-b1cd-4376-b481-a9ad120016f6 MEDIUM 6.1 The mywebcounter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in ve… wordfence
57162a5e-5f5d-4b22-bb7f-0ff65332910b
< 2.8.1
MEDIUM 6.1 The Stockdio Historical Chart plugin before 2.8.1 for WordPress is affected by Cross Site Scripting (XSS) via stockdio_c… wordfence
5715f3d3-8b88-45bc-a858-3911eeaaf045 MEDIUM 6.1 The Post Title Counter WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the notice parameter found i… wordfence
5705c3bd-fb1f-407b-b7ab-5e3dbf909a7f
< 3.9
MEDIUM 6.1 The Youtube Vimeo Video Player and Slider WP Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
57051491-a56b-4a3a-9383-ba63585550be
< 2.2.30
MEDIUM 6.1 The tab GET parameter of the settings page is not sanitised or escaped when being output back in an HTML attribute, lead… wordfence
56fad8de-6646-4305-83a9-0ed443c3aa7d
< 4.4.5
MEDIUM 6.1 The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to,… wordfence
56f46330-20d2-48f2-8e23-cc8f968db4b8 MEDIUM 6.1 The Admin Menu Editor WordPress plugin through 1.0.4 does not sanitize and escape a parameter before outputting it back … wordfence
56f39e64-ff29-4b9f-acd1-a45d3ce5cb18 MEDIUM 6.1 The XPD Reduce Image Filesize plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
56f365dd-9b6b-402a-8a09-35a26684cebf
< 1.3.4
MEDIUM 6.1 The Institutions Directory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
56ecffec-06f3-4852-be36-5ed6f5db133b
< 1.1.10
MEDIUM 6.1 The IP2Location World Clock plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
56d8516d-f2e6-4648-b8e6-75d6fb357ba8
< 1.1.1
MEDIUM 6.1 The DX Dark Site plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
56cd4317-46e1-4e6c-a586-b3aacb189dd8 MEDIUM 6.1 Multiple cross-site request forgery (CSRF) vulnerabilities in the iTwitter plugin 0.04 and earlier for WordPress allow r… wordfence
56c719dc-b97a-4eb1-ae7a-e435c2f5a69e
< 3.1.4
MEDIUM 6.1 The WordPress reCAPTCHA for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
56b3d629-014c-47b3-9726-4086e544011b MEDIUM 6.1 The Libsyn Publisher Hub plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.… wordfence
56acae44-6f22-440c-bee1-4cd3831a99ec
< 5.4
MEDIUM 6.1 The democracy-poll plugin before 5.4 for WordPress has XSS via update_l10n in admin/class.DemAdminInit.php. wordfence
56abcad2-5be0-422c-a33f-91bc123364e5
< 3.0.72
MEDIUM 6.1 The eCommerce Product Catalog plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘term’ pa… wordfence
← Prev 925 926 927 928 929 930 931 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top