๐Ÿ›ก๏ธ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 951 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3e742b21-1097-459c-8c67-46d105e7b6e8
< 3.1
MEDIUM 6.1 The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in th… wordfence
3e6678db-6933-4a38-b704-214de7197852 MEDIUM 6.1 The Loginplus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.… wordfence
3e61c868-b430-4aa6-8664-ae237db73d66
< 1.1.47
MEDIUM 6.1 Cross-site scripting vulnerability in BackupGuard prior to version 1.1.47 allows an attacker to inject arbitrary web scr… wordfence
3e57ba2b-a95c-4410-9ba6-a66c6da36883 MEDIUM 6.1 The Premium WP Suite Easy Redirect Manager plugin 2.18.18 for WordPress has XSS via a crafted GET request that is mishan… wordfence
3e477f41-8765-472a-b48b-d381cf7de5c6 MEDIUM 6.1 The Photolio Theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerable versio… wordfence
3e471ef4-94c1-47d9-98ae-f79f7662e21a
< 4.3.1
MEDIUM 6.1 The Woocommerce Open Close โ€“ Best Business Schedules Manager plugin for WordPress is vulnerable to Reflected Cross-Sit… wordfence
3e46e6f4-c157-4d7a-8f50-f8c8213460fa MEDIUM 6.1 The ZoomSounds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.… wordfence
3e3c9f08-9e73-4791-b6ca-2c8b9dc3fb81
< 21.2.8.1
MEDIUM 6.1 The Photos and Files Contest Gallery โ€“ Contact Form, Upload Form, Social Share and Voting Plugin for WordPress plugin … wordfence
3e282a23-07e8-464a-9d6e-a2eb506064bc
< 1.5.4.7
MEDIUM 6.1 The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the โ€˜term_i… wordfence
3e1e6fb1-af66-460e-9fb1-8d14a8cbbea5
< 1.73
MEDIUM 6.1 The Album and Image Gallery with Lightbox โ€“ Flagallery Photo Portfolio plugin for WordPress is vulnerable to Reflected… wordfence
3e15668b-8f05-4f1f-9cca-24f88081bdec MEDIUM 6.1 The AT Internet SmartTag plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
3e152d9f-4fb9-41b9-baa4-b1bebac89641
< 2.1.2
MEDIUM 6.1 The WordPress Multisite Content Copier/Updater Pro before 2.1.2 does not sanitise and escape the s parameter before outp… wordfence
3e1497d7-64e8-4c2a-97f7-8dfa3bbc2820
< 1.8.0.4
MEDIUM 6.1 The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '$_SE… wordfence
3e1425e6-799b-48fb-b04c-36b906297150
< 1.06
MEDIUM 6.1 The Images Asynchronous Load plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
3e0e022b-857d-4e7f-99d2-3837014c254e
< 1.55.5
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in posts/videowhisper/r_logout.php in the Video Posts Webcam Recorder plugin 1.… wordfence
3e062157-bfde-46f8-92a1-2235dd9822f7 MEDIUM 6.1 The UTM tags + Landing page + "gclid" tracking for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Reque… wordfence
3e03ecc0-5ca1-4d64-a6d7-257325bcc5cb MEDIUM 6.1 The Product Category Tree plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'term_id' paramet… wordfence
3dffd377-22e5-4fa3-879a-4924d01fd32d MEDIUM 6.1 The WP Dynamic Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
3ded9f9a-fc89-4618-a762-24c23437734c MEDIUM 6.1 The wp-flickr-press plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
3de459ce-a4e7-443a-abd6-b8e1c9c1d184
< 4.4
MEDIUM 6.1 The GD Mail Queue plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
3dc7355d-9c14-4633-985e-e0357c6210f7 MEDIUM 6.1 The Banner Garden Plugin for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'typ… wordfence
3db65e14-50c6-4afe-84e5-0785fe9bf77a
< 1.0.5
MEDIUM 6.1 The BestWebSoft's LinkedIn plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
3dad7ba6-bac4-4f1a-83f5-fd5769cd4a45
< 3.2.14
MEDIUM 6.1 The Ninja Forms plugin before 3.2.14 for WordPress has XSS. wordfence
3da3a409-6738-4774-bf98-2ebce539c198 MEDIUM 6.1 The uDesign - Responsive WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions… wordfence
3d85d609-781b-4f82-af57-124767f9d333
< 5.2.3
MEDIUM 6.1 The ์›Œ๋“œํ”„๋ ˆ์Šค ๊ฒฐ์ œ ์‹ฌํ”ŒํŽ˜์ด โ€“ ์šฐ์ปค๋จธ์Šค ๊ฒฐ์ œ ํ”Œ๋Ÿฌ๊ทธ์ธ plugin for WordPress is vulnerable to Refle… wordfence
← Prev 948 949 950 951 952 953 954 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top