πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 943 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
472b523f-b987-4da0-8533-54ae076d7a6b MEDIUM 6.1 The Email Artillery (MASS EMAIL) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Reques… wordfence
47122866-8e40-42bc-84ed-60fc81247320 MEDIUM 6.1 The Advanced Schedule Posts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown paramete… wordfence
46fd4e5d-e1d7-4de6-ae24-66e260a1b288
< 1.0.4.3
MEDIUM 6.1 The TableOn plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.4… wordfence
46f5d1fa-dba7-4882-be29-39dc281d7278
< 2.1.9
MEDIUM 6.1 The CodeBard's Patron Button and Widgets for Patreon plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
46e2693a-809f-43f9-b189-35a0c73bf34e MEDIUM 6.1 The search feature of the Mediumish WordPress theme through 1.0.60 does not properly sanitise it's 's' GET parameter bef… wordfence
46c9dae7-d811-4b59-94c1-71a83652a14d
< 3.1.9
MEDIUM 6.1 The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions… wordfence
46b9ca33-e140-48de-88bc-3dc1dc338c70 MEDIUM 6.1 The WP Post Category Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions … wordfence
46a16b7b-6de4-49a6-83e3-309f8ab43505
< 1.3.9
MEDIUM 6.1 search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS. wordfence
46a022ff-7ec8-48bc-b0ae-8e925ea3f361 MEDIUM 6.1 The Magic Post Voice WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the ids parameter found in the… wordfence
467e0946-cfbb-4ea3-b2d9-db21d0f182cd
< 1.3.5
MEDIUM 6.1 PageLayer before 1.3.5 allows reflected XSS via the font-size parameter. wordfence
4671556c-d902-4294-9e25-47e3d0e2ca98
< 0.45.16
MEDIUM 6.1 The Sermon Browser plugin for WordPress is vulnerable to multiple Cross-Site Scripting in versions up to, and including,… wordfence
466d6087-1e4d-4010-b3c7-87e9e2d64f06
< 1.2.7
MEDIUM 6.1 The Christmas Greetings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the code parameter in a… wordfence
466171e7-575d-4fc1-8005-8704904b7725
< 12.4.0
MEDIUM 6.1 The Order Delivery Date for WP e-Commerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '… wordfence
464fda21-5efe-4565-9b21-85d6c458a6a1 MEDIUM 6.1 The Dooodl plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.3.0 … wordfence
463fd745-92ea-4e55-b470-a5f08884169f
< 1.1.47
MEDIUM 6.1 The Backup Guard plugin before 1.1.47 for WordPress has multiple XSS issues. wordfence
463c11ba-f307-4ab5-8de7-09f3a113cddd
< 2.8.1
MEDIUM 6.1 The Brizy Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.8… wordfence
462ea9c3-ed33-46f2-8d60-ba024f369561 MEDIUM 6.1 The LinkLaunder SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
4625d217-99d4-47d8-b093-fe55a3018348
< 2.21
MEDIUM 6.1 The Sticky Menu & Sticky Header plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab paramet… wordfence
4618c39d-219e-4fc3-be98-15303bc8483f MEDIUM 6.1 The WP Ajax Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'eid' parameter in… wordfence
45f581dc-d424-4cda-aa03-016e9b5ee1e5 MEDIUM 6.1 The OSD Subscribe WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the osd_subscribe_message paramet… wordfence
45f3568c-b6d9-4d00-a8cd-571443d80fd3
< 2.44
MEDIUM 6.1 The Memory Usage, Memory Limit, PHP and Server Memory Health Check plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
45ee8b10-6758-45c8-835e-197ad6a9284a MEDIUM 6.1 The Post Carousel & Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
45dd22d4-9a51-4569-a756-1f1a5f8626c1
< 1.1.21
MEDIUM 6.1 The WordPress Affiliates Plugin β€” SliceWP Affiliates plugin for WordPress is vulnerable to Reflected Cross-Site Script… wordfence
45d5a677-9b8b-4258-9cfb-101b0f0e6f6f
< 1.82.6
MEDIUM 6.1 The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for… wordfence
45d3cff1-3a86-4b79-bf43-1623d41ac821
< 3.4.1
MEDIUM 6.1 The total-security plugin before 3.4.1 for WordPress has XSS via several parameters. wordfence
← Prev 940 941 942 943 944 945 946 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top