πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 934 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
514184b0-aa54-41d1-9aa0-86d120ae79c7 MEDIUM 6.1 The Mapping Multiple URLs Redirect Same Page Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… wordfence
513f4a39-afba-4819-abf2-6ed168d11dfe
< 2.2.4
MEDIUM 6.1 Cross-site scripting vulnerability in Welcart e-Commerce versions prior to 2.2.4 allows remote attackers to inject arbit… wordfence
5138ed4c-3e9c-45da-917e-e8d8396a62f1
< 1.3.1
MEDIUM 6.1 The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navig… wordfence
51350be0-8c20-4d53-9dc8-be8a13f319cb MEDIUM 6.1 The Infinite Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
5123c672-e769-4d44-9912-e159d3e186c1 MEDIUM 6.1 The WP-SOS-Donate Donation Sidebar Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVE… wordfence
51214710-3fd4-426c-95fa-f29735822c54 MEDIUM 6.1 The ldap_login_password_and_role_manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
5113b58b-7d2e-40cd-8669-a5597321106f
< 7.3.5
MEDIUM 6.1 The Quiz And Survey Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters i… wordfence
510ef568-fe5e-427e-a5ab-76c65250ade3 MEDIUM 6.1 The Vistered Little theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the the URI (REQUEST_URI) th… wordfence
510b1390-b8e6-41b5-8691-3043fa3fb47d
< 6.9.5
MEDIUM 6.1 The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitize and escapes some of its settings, which could … wordfence
5102d03b-368f-410e-9c0f-a90caa7d28ec MEDIUM 6.1 The HTML5 Lyrics Karaoke Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the swfupload.s… wordfence
50f88c71-e57b-4792-b579-0e33f2d637d0
< 1.0.2
MEDIUM 6.1 The WPBookit plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.… wordfence
50f58944-1a12-4bac-9f90-8b0e1d109d11
< 2.8.1
MEDIUM 6.1 wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access t… wordfence
50f2cc05-b1f8-4f87-8ede-0df475d81a02
< 2.6
MEDIUM 6.1 The Fade Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2… wordfence
50ebe03e-9425-41ef-801e-97e42670652f MEDIUM 6.1 The WP AntiDDOS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
50c33c8d-4488-4f9e-bc58-21cb8cd679e6
< 1.6.9
MEDIUM 6.1 XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slide… wordfence
50bbcfcb-7001-42e7-926c-ec4bf4ea35f6
< 1.2.9
MEDIUM 6.1 The WP Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
50912c68-1bc8-4792-b624-4edda17ae43f MEDIUM 6.1 The Garee's Flickr Feed for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions… wordfence
5083509e-84e4-4bd3-9023-b458312b1886
< 7.0.1
MEDIUM 6.1 The Jetpack plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 7.0 due to insu… wordfence
507fe5f4-3ac3-4e48-835e-66bad8bffc88
< 6.67
MEDIUM 6.1 The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to… wordfence
507e9a3a-6e69-4c16-abbb-fb3f3096e03a
< 1.5
MEDIUM 6.1 The 5sterrenspecialist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
50798706-ad0d-431e-ac5f-57a0606c6f94
< 3.0.9
MEDIUM 6.1 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
507464cf-43a3-49bd-b8d8-9bc8030670e0 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in bvc.php in the Votecount for Balatarin plugin 0.1.1 and earlier for WordPres… wordfence
506f101c-ffec-415d-92dc-99cb7384af95 MEDIUM 6.1 The Simple add pages or posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
50167c70-40f3-4beb-9171-ece066d2c3de MEDIUM 6.1 The Country Blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
4ffeec7b-cd4d-4555-acc0-22b44f237da6
< 1.2.4
MEDIUM 6.1 The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id,… wordfence
← Prev 931 932 933 934 935 936 937 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top