🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 950 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3fa63ac2-b063-40a1-beaf-a27f56688347
< 1.4.2
MEDIUM 6.1 The Jobica Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
3f8321a7-863c-43ab-a42a-e01d60101c3b
< 3.23.3
MEDIUM 6.1 The Stock Ticker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in the ajax_stockticker_symbol_sea… wordfence
3f594989-8db3-41c8-9089-b4e2d995270e
< 1.2.3
MEDIUM 6.1 The Order XML File Export Import for WooCommerce Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi… wordfence
3f5413be-76b8-457c-9236-3ef760f46d40 MEDIUM 6.1 The Custom Metas plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘/wp-content/plugins/cus… wordfence
3f39c478-7b64-4afc-8c3f-9409e105954a
< 2.6.1
MEDIUM 6.1 The OptinMonster WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient input validation i… wordfence
3f3448ad-61b3-4eac-a5ba-9bea41c85fd3 MEDIUM 6.1 The Glass WordPress plugin through 1.3.2 does not sanitise or escape its "Glass Pages" setting before outputting in a pa… wordfence
3f18a07f-c7de-49ac-9a11-f9cbc48b125a MEDIUM 6.1 The DJ EmailPublish WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SE… wordfence
3f18437c-2258-4f5b-a114-fb099f115f2e MEDIUM 6.1 Cross-site request forgery (CSRF) vulnerability in the Dropdown Menu Widget plugin 1.9.7 for WordPress allows remote att… wordfence
3f0b212a-969b-4cd3-a31c-40b9ff9dce5f
< 1.7.1
MEDIUM 6.1 The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via … wordfence
3f08fd6e-4c1b-40e7-92ba-72cdd03ff585
< 6.4b
MEDIUM 6.1 The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back… wordfence
3eff6af4-0553-4554-bce2-e355a4a06eec MEDIUM 6.1 The WooCommerce HTML5 Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
3ee49082-5255-4ab7-9562-bd786a32382c MEDIUM 6.1 The Turn off all comments WordPress plugin through 1.0 does not sanitise and escape the rows parameter before outputting… wordfence
3edce64d-13c2-454a-b5da-0454453f69cb
< 12.1.21
MEDIUM 6.1 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' and '… wordfence
3edc40b7-5cf6-413b-80c5-b001934bedc3 MEDIUM 6.1 The GNU-Mailman Integration WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the gm_error parameter … wordfence
3ed93cc1-66dd-414b-9c8c-5e0db44e1cf2 MEDIUM 6.1 The Migrate Posts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
3ed6d5e6-1094-46ec-afb9-43c142f334ed
< 1.3.4
MEDIUM 6.1 The Plausible Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page-url parameter … wordfence
3ed45d70-a528-47ee-84c9-26948dfe91f1
< 1.3.8
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in platinum_seo_pack.php in the Platinum SEO plugin before 1.3.8 for WordPress … wordfence
3ed1ab41-d4ad-4447-8914-f375b196d31b MEDIUM 6.1 The WpDevTool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
3ecdd962-7d85-4a60-956d-1e8a49507ab2
< 0.9.5
MEDIUM 6.1 The salavat counter Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter… wordfence
3ec48620-4969-43ff-bf42-72188dba001a MEDIUM 6.1 The Send to Twitter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
3ebebe75-155a-4097-95ec-f31c6047f19a MEDIUM 6.1 The Canva – Design beautiful blog graphics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all… wordfence
3eb4b3e7-6aad-4201-b48b-c8d788eb8acf
< 1.1.8
MEDIUM 6.1 The Limit Attempts by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catego… wordfence
3eab1e93-ecf1-4ac6-95b0-9a58c2de867a
< 1.7.9.1
MEDIUM 6.1 The Cooked plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.7.9 … wordfence
3e9bdb9d-bffe-4f6f-bb91-3dc5f7009f68 MEDIUM 6.1 The MultiSite Clone Duplicator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
3e8fe670-5072-43c2-8ff6-e8730d24b9cd MEDIUM 6.1 The Qiniu Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the swfupload.swf file in ve… wordfence
← Prev 947 948 949 950 951 952 953 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top