πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 930 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5570b8ef-6fb9-4f9e-be39-d8c615d1abab
< 1.2
MEDIUM 6.1 The SendPress Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'listID' & 'subsc… wordfence
556f6e7d-dbb4-4030-b6f9-8709135ae660 MEDIUM 6.1 The 4 author cheer up donate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
5569ec0f-eeb6-433f-bb49-336abae2a29a MEDIUM 6.1 The Velvet Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions … wordfence
5537c46d-1df3-4d24-b1c0-851c22c6ae79 MEDIUM 6.1 The SingSong plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.… wordfence
55367b9b-8ae1-4282-bf9f-8fb3848eb579 MEDIUM 6.1 The Admission AppManager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter in v… wordfence
552d2d0d-1f4a-4557-ba8e-9f63acbfffba
< 2.4.3
MEDIUM 6.1 The Wyzi Theme was affected by reflected XSS vulnerabilities in the business search feature wordfence
550a8107-f639-4edc-9aad-1943d032cc26 MEDIUM 6.1 The Custom Website Data WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter found in t… wordfence
54fff686-3c5a-4e75-af04-05700db4f3f0 MEDIUM 6.1 The Thebe theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3.0 du… wordfence
54e7ccaf-2b16-4e36-a8ec-8f1f61193ffd
< 0.810
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers t… wordfence
54e330e7-d305-4254-a9e9-4d7f2c54c51c MEDIUM 6.1 The Forms Ada plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜p’ ($page_nav) parameter… wordfence
54def910-b934-4a48-b7fe-7165917b01ca MEDIUM 6.1 The Studiocart plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.… wordfence
54c79532-588d-4afd-ad01-199b5c4ce4d0
< 4.1.6
MEDIUM 6.1 The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
54c563fb-efc2-44f2-9b1d-7c4a377a2565 MEDIUM 6.1 The Vice Versa plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.… wordfence
54c38be0-ffe7-4fa4-b5c9-cb717c11aed5
< 118
MEDIUM 6.1 The Simple URLs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' parameter in vers… wordfence
54c1809d-cff3-4800-8945-bffad7f03d33 MEDIUM 6.1 The JSON Structuring Markup plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
54c154a9-e751-4e8f-a26e-7eb208fa7ffe
< 0.7.1.6
MEDIUM 6.1 The Connections plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 0.7.1.5 due… wordfence
54c0146d-3193-4fde-9082-600ab97160e6 MEDIUM 6.1 The Twispay Credit Card Payments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
54b88702-ec41-414b-87f1-1859b130a713 MEDIUM 6.1 The CloudNet360 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all ver… wordfence
54ac4a5a-b0f4-458e-b2c7-9884c7a2138d MEDIUM 6.1 The Theme Blvd Sliders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
54a5146e-53f8-455e-a80a-b9c60cb46984 MEDIUM 6.1 The Block Collection for You – WP Block Pack plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in a… wordfence
549d4aa4-9f34-4453-93ec-1561278f7959 MEDIUM 6.1 The Accordion Slider PRO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
54904fb0-4737-414c-bc9a-f5b040b59286 MEDIUM 6.1 The Automotive Car Dealership Business WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripti… wordfence
5486d50c-8544-4368-b58b-66024a8ae86d
< 8.6.01.005
MEDIUM 6.1 The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 8.5… wordfence
547e5814-0201-4dbf-9d2d-8028ca055402
< 5.0.1.9
MEDIUM 6.1 The RegistrationMagic WordPress plugin before 5.0.1.9 does not sanitise and escape the rm_search_value parameter before … wordfence
547008fe-2585-4089-a710-71a83ae3d829
< 6.2.9
MEDIUM 6.1 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vul… wordfence
← Prev 927 928 929 930 931 932 933 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top