ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 953 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3d0114d9-de95-444b-9820-e775bff32d53 MEDIUM 6.1 The Photo Express for Google plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
3cdf6ba0-2866-4347-8518-bb1d2e40bab3 MEDIUM 6.1 The dream gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
3cde6acf-8ef7-4eae-a10d-5a18fcf29799
< 2.21.3
MEDIUM 6.1 The xili-language plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
3cdad887-dafa-4cf8-ac78-87b9b9b989e2
< 1.6.0
MEDIUM 6.1 The Webcamconsult plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
3ccd7144-fde1-4ade-ac66-5ea14cdbc616 MEDIUM 6.1 The Notices WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] val… wordfence
3cc23af6-c7a6-4f10-89ab-34a0b462b325 MEDIUM 6.1 The WP Finance plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menu' parameter in all vers… wordfence
3cc196c8-1f8f-4ddd-9f27-45d318895b91 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in wordpress-processing-embed/data/popup.php in the Processing Embed plugin 0.5… wordfence
3cb95e28-449b-4ed7-9c44-ade171e0ecee
< 5.3.9
MEDIUM 6.1 The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field. wordfence
3cb84ba3-b403-4a9d-b1a7-92aa947310ac
< 3.3.47
MEDIUM 6.1 The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' paramete… wordfence
3cb30d2b-84f2-433e-bb9e-713486b759ae
< 1.3.67
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Role Scoper plugin before 1.3.67 for WordPress allows remote attackers t… wordfence
3cb047d0-0056-432c-bae3-3ab926e39bcd MEDIUM 6.1 The TWChat – Send or receive messages from users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
3ca760ea-e062-413e-ac92-520922129937
< 1.9.8.5
MEDIUM 6.1 The Form Builder | Create Responsive Contact Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
3c88033f-d2e8-488c-9e19-ff806a346b57 MEDIUM 6.1 The spam-stopper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
3c86a625-9c2f-4e17-938b-82766783384e MEDIUM 6.1 The Ghostwriter theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
3c73fbbf-ac70-413b-b378-1a93b167aeff MEDIUM 6.1 The Bauernregeln plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
3c730688-16aa-4593-baa7-4a64f83d88eb
< 5.0.0
MEDIUM 6.1 The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Reflected Cross-Site Scri… wordfence
3c6fd92f-a541-42d1-8093-c3a4a61ab39b
< 1.3.67
MEDIUM 6.1 The Photo Gallery by 10Web plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, … wordfence
3c6841e7-fddf-45b1-9d18-00911325b1d3
< 1.5.3
MEDIUM 6.1 The VikRestaurants Table Reservations and Take-Away plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
3c64120f-254f-4deb-93bc-d24e366631ed MEDIUM 6.1 The 1g-music-share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘data’ parameter in … wordfence
3c49c7db-50de-4f1d-acfa-d12a84a42d94 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in RSS Feed Reader 0.1 for WordPress allo… wordfence
3c48819a-5ca1-4262-b995-1c4621fcfadc
< 1.0.4
MEDIUM 6.1 The Post Connector plugin before 1.0.4 for WordPress has XSS via add_query_arg() and remove_query_arg(). wordfence
3c455509-9cbb-4a77-b28f-921beeeede0e
< 2.7.10
MEDIUM 6.1 The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outp… wordfence
3c182d41-edce-473c-9f20-e480072e06d0
< 3.2.1
MEDIUM 6.1 The WooCommerce – Payphone Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up… wordfence
3c1814c7-1ca0-42e6-a819-7e258f34ecac
< 1.0.33.2
MEDIUM 6.1 The Mingle Forum plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, an… wordfence
3c12074f-9a19-49cb-9d74-b759c7391d3c
< 3.7.0
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in includes/api_tenpay/inc.tenpay_notify.php in the Alipay plugin 3.6.0 and ear… wordfence
← Prev 950 951 952 953 954 955 956 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top