🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 952 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3d819b54-f057-4875-8e40-f5c77db2e5fd
< 1.5.1.15
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPr… wordfence
3d7ca3ff-eae4-425f-8340-9d9b4952ce4a MEDIUM 6.1 The Ultimate Noindex Nofollow Tool plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
3d76a807-d81d-45fc-a571-625a6ecf670b
< 1.6.6
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Cover WP theme before 1.6.6 for WordPress allows remote attackers to inj… wordfence
3d6affb6-bbc1-40aa-8633-ba0f06c10fe1
< 0.1.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in js/window.php in the Navis DocumentCloud plugin before 0.1.1 for WordPress a… wordfence
3d69a674-c6cf-406f-bc11-175fad8e60c8
< 6.6.9
MEDIUM 6.1 The PayPlus Payment Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
3d667f97-5072-4119-84d8-7104fd63559c
< 1.3.1
MEDIUM 6.1 The Chessgame Shizzle plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'cs_nonce' parameter … wordfence
3d6488ce-e34a-4b23-806d-fa2fb948ea8f
< 3.1.8
MEDIUM 6.1 This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order da… wordfence
3d6199e1-c102-45d2-b24b-0eab4edf857b
< 2.22.9
MEDIUM 6.1 The FraudLabs Pro for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
3d5c4bf6-36f7-4e6d-a012-95594e3d93f8 MEDIUM 6.1 The Arya Multipurpose theme for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.0.5 … wordfence
3d599ed8-ba30-4f12-83f5-be452bc1ae35
< 3.1.11
MEDIUM 6.1 In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_i… wordfence
3d55bee0-1638-4e64-9f68-3b13384be799 MEDIUM 6.1 The Easy Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
3d501415-39ab-4c2a-bcd3-fda97b7a3235 MEDIUM 6.1 The kento_email_subscriber_ajax AJAX action of the Email Subscriber WordPress plugin through 1.1, does not properly sani… wordfence
3d4bb4b6-9565-4a8a-aae3-ba863ef42ddb
< 3.0.3
MEDIUM 6.1 The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the dbstatus parameter … wordfence
3d4838b8-7a9d-43b7-a577-7d7ae8bac5fa MEDIUM 6.1 The Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1.… wordfence
3d400eae-7d5f-490b-841e-ffb749016c1d MEDIUM 6.1 The Debug-Bar-Extender plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
3d2f77cf-bc97-47ba-b3a6-5bdc1452715c MEDIUM 6.1 The Geoportail Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
3d2dde13-2940-478e-8e2b-baf60003754a
< 5.0.11
MEDIUM 6.1 The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Refl… wordfence
3d2d22bb-e29e-4d4b-a97d-e128777712b0 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in falha.php in the Bradesco Gateway plugin 2.0 for Wordpress, as used in the W… wordfence
3d2031c4-56ee-4779-84fe-c6679ab1c6f4
< 5.2.19
MEDIUM 6.1 The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to Reflected Cross-Site Script… wordfence
3d1513b5-4c52-4987-a468-c513f4e5d190
< 2.0.04
MEDIUM 6.1 The Contribuinte Checkout plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
3d13454c-0c46-4b16-8e0e-bbfcf2338230 MEDIUM 6.1 The EasyAzon – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
3d12d692-231b-4e15-a119-80fd74566af4
< 4.0.9
MEDIUM 6.1 The Webmention plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘replytocom’ parameter i… wordfence
3d0f5e62-aa81-4a2e-8187-917391548a31 MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in callback.php in the efence plugin 1.3.2 and earlier for WordPress… wordfence
3d0afaca-e58a-4b20-97ba-0125648a269b
< 3.0.0
MEDIUM 6.1 The Real Seguro Viagem plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
3d065c2a-da7d-469a-b57d-f2fd5b760ff4
< 3.3.70
MEDIUM 6.1 The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi… wordfence
← Prev 949 950 951 952 953 954 955 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top