πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 931 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
546c6222-6ffa-41cb-8fff-d2c3cd37ed1f MEDIUM 6.1 The OrangeBox plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0… wordfence
5463a730-a8cf-40c9-83fc-3e451e4db1c9
< 3.1.4
MEDIUM 6.1 The CM Tooltip Glossary – Better SEO and UEX for your WP site plugin for WordPress is vulnerable to reflected Cross-Si… wordfence
545d5a0f-2f7d-4d2e-9584-cea6449fe045 MEDIUM 6.1 The My Login Logout Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
54560426-a9c9-4a60-9690-8e797e0e7e8d MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the WP GuestMap plugin 1.8 and earlier for WordPress allow remote… wordfence
54516240-7f2e-4bb8-a252-bb4259b724d7 MEDIUM 6.1 The Related Posts via Categories plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
54285c08-c9c8-4576-b1e8-e3b1c584c4bb
< 2.0.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 and 2.0.1 allows remote attackers to inject… wordfence
54245c83-a0ae-454f-af80-25383b90948d MEDIUM 6.1 The Terms Dictionary plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
54212d4d-5ff7-4ca4-82f5-10ade4c4a1c0
< 11.49
MEDIUM 6.1 The WPMobile.App β€” Android and iOS Mobile Application plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
54140e73-0eb0-4ef3-a8e2-8e7a0d321ca5 MEDIUM 6.1 The Explara Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
541012b2-5d52-452b-85ec-62d3c56d2bc4
< 2.0.19
MEDIUM 6.1 The Listeo Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 2.0.19 due to ins… wordfence
540d2495-7ad4-428c-b86e-9af73d0ebe51
< 1.2.7
MEDIUM 6.1 The Ad Invalid Click Protector (AICP) WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the page par… wordfence
5409a9c0-df17-4663-96c7-aced7b0f8c70
< 3.5.9
MEDIUM 6.1 The Responsive HTML5 Audio Player PRO With Playlist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
54044b8c-52f2-4887-b67c-ed78023da3ff
< 2.6.7
MEDIUM 6.1 The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPres… wordfence
540236b8-ff7a-4171-812b-29d3c88a881a MEDIUM 6.1 The Boot Store theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tcp_register_error' paramete… wordfence
53ef1383-55a7-40ea-b382-6804e10efa84 MEDIUM 6.1 The hpb seo plugin for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
53e01cb5-f8c2-4151-b0d6-13422382fd13
< 5.1.4
MEDIUM 6.1 The WordPress Internal Link Optimiser plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
53d2f416-4b0f-49b7-af14-fbb225aac34d MEDIUM 6.1 The Purity Of Soul theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
53ac7001-e381-4bfb-8749-6f9df10dcab5 MEDIUM 6.1 The WordPress Activity-o-meter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
53a58c45-b7fd-469e-8c67-4f20707f2363 MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the WP SimpleMail plugin 1.0.6 for WordPress allow remote attacke… wordfence
5394623b-e9ee-4047-bfe3-d7f6374993cd
< 0.85
MEDIUM 6.1 The Google Forms plugin for WordPress is vulnerable to Cross-Site Scripting via the 'page' parameter in versions before … wordfence
539300b9-3e8e-4c20-93a6-b6eb1588cc6c MEDIUM 6.1 The Saragna plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0 d… wordfence
538616b8-0c23-42b7-a694-dde69af9e3b9 MEDIUM 6.1 The Tuaug4 theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4 due… wordfence
537b6f36-ae45-465a-b139-6753d50d8e10 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in index.php in the (1) Blix 0.9.1 and (2) Blix 0.9.1 Rus themes for WordPress … wordfence
537acaf7-8d44-484d-9516-774a3de5573f
< 3.6
MEDIUM 6.1 Stored XSS was discovered in the Easy Testimonials plugin 3.5.2 for WordPress. Three wp-admin/post.php parameters (_ikcf… wordfence
53686d01-b60c-4324-895e-2fae3ccfa3c9
< 1.8.12
MEDIUM 6.1 The MP3-jPlayer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜mp3’ parameter in vers… wordfence
← Prev 928 929 930 931 932 933 934 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top