🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 933 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5247b658-c655-4855-ad98-695071b0ede6 MEDIUM 6.1 The UberSlider Ultra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
523cfed4-0422-40f3-8d81-d7862bcb1792 MEDIUM 6.1 The MyTube PlayList plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘addplaylistid’ par… wordfence
52343971-65a8-4efd-ad6d-521936730b27 MEDIUM 6.1 The chatplusjp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
52293a10-4240-4a6b-a05b-33675a4ed6b6 MEDIUM 6.1 The WC1C plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without ap… wordfence
5224233f-6cb4-4fd9-b25b-e32db612cb7f MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in vncal.js.php in the VN-Calendar plugin 1.0 and earlier for WordPr… wordfence
520730e0-e085-4bbf-a1c7-497b9ae2da3c MEDIUM 6.1 The BP Profile as Homepage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
5204d111-3dd5-4dd0-bf1a-79ec2900b4d8
< 4.9.6
MEDIUM 6.1 The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
51e1a30e-774e-4478-be34-486ed4142a7d
< 3.4.3
MEDIUM 6.1 Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead t… wordfence
51d14f45-4c30-4225-998d-f4f829e09bc0
< 2.5.8
MEDIUM 6.1 The GetResponse Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o… wordfence
51cd834e-1b18-4702-9c6c-db7f34f2c687
< 5.4.7
MEDIUM 6.1 WordPress Core is vulnerable to prototype pollution in various versions less than 5.8.1 due to a vulnerability in the Lo… wordfence
51c95763-fd42-4b97-8dca-1ed11615709a MEDIUM 6.1 The Twitter @Anywhere Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
51c1c4ee-c17f-4565-b800-f306569fc502 MEDIUM 6.1 The websimon-tables plugin through 1.3.4 for WordPress has wp-admin/tools.php edit_style id XSS. wordfence
51b7c8f3-3d55-44c9-896c-c3ae19f15a34 MEDIUM 6.1 The Estatebud – Properties & Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
51b725e4-b088-4f6b-8810-87a39ca952ff
< 1.0.7
MEDIUM 6.1 The liquid-speech-balloon (aka LIQUID SPEECH BALLOON) plugin before 1.0.7 for WordPress allows XSS with Internet Explore… wordfence
51b626e1-89c0-49b9-bfeb-32005e8e78d6
< 3.13.0
MEDIUM 6.1 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is… wordfence
51b60e28-fb43-434a-88ca-3c73a8e89d40
< 3.1.5
MEDIUM 6.1 The akismet plugin before 3.1.5 for WordPress has XSS. wordfence
51b56dc5-0d2d-4fa9-872c-4193f61c165f
< 1.2.1
MEDIUM 6.1 The VikRentItems Flexible Rental Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
51ac25ef-e5b9-4f5c-a792-fff4ceba96e1
< 0.1.9.6
MEDIUM 6.1 The Specific Content For Mobile – Customize the mobile version without redirections plugin for WordPress is vulnerable… wordfence
51a1c2de-56be-4487-874a-a916e8a6992a
< 1.0.14
MEDIUM 6.1 The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
5196a9f2-177d-48e1-b0dc-72e0727132d6
< 2.3.2
MEDIUM 6.1 The WordPress Comments Import & Export plugin for WordPress is vulnerable to CSV Injection in versions up to, and includ… wordfence
5190b5ac-a12c-45ea-97fd-2d86bc2b090c
< 6.21.01
MEDIUM 6.1 The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
51880262-78ad-4791-8e3d-f6718de9f2a2
< 4.27
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in ls/htmlchat.php in the VideoWhisper Live Streaming Integration pl… wordfence
5172cf1e-9ebd-40cd-846c-82d80211ca32 MEDIUM 6.1 The SVT Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
516d40c7-fc27-45df-bb08-fbafcd1c81a4 MEDIUM 6.1 The News Publisher Autopilot plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
51550d42-2c75-4cb1-9bf9-da27ebf83ac0 MEDIUM 6.1 The amr shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
← Prev 930 931 932 933 934 935 936 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top