πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 954 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3c0b0bf7-55dd-40a1-8f12-f0ec0315c0ec
< 2.0.8
MEDIUM 6.1 The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outpu… wordfence
3c07dec6-ddb7-45df-8bdf-57f562102c4b
< 20260301
MEDIUM 6.1 The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'c' parameter in versions… wordfence
3bf6671d-f481-4fe5-b966-2591ab76b0b5 MEDIUM 6.1 The Last.fm Recent Album Artwork plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
3be71ddf-bb6f-492f-8d89-d0d850b27233 MEDIUM 6.1 The Felan Framework plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
3bd5c774-2c5b-47d5-9eae-614f2a1b8529 MEDIUM 6.1 The FontMeister plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜kit’ parameter in vers… wordfence
3bc0951e-8ada-4221-b154-101bad33a183
< 1.3.9
MEDIUM 6.1 The ARI Fancy Lightbox WordPress plugin before 1.3.9 does not sanitise and escape the msg parameter before outputting it… wordfence
3bb4a3f3-495d-4ece-9436-9c317688982c
< 1.4
MEDIUM 6.1 Wordpress Plugin Vospari Forms version < 1.4 is vulnerable to a reflected cross site scripting in the form submission re… wordfence
3bb1ac5d-01aa-48d8-85fe-ac6b359b6815 MEDIUM 6.1 The File Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.… wordfence
3ba98b0b-0772-4871-9892-c6354ceaf614
< 1.2.7
MEDIUM 6.1 The Google SEO Pressor for Rich snippets plugin for WordPress is vulnerable to Cross-Site Scripting via several paramete… wordfence
3b98668e-a20f-49a3-a6d6-6da6d1c044d6
< 2.0.2
MEDIUM 6.1 The IMPress Listings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in the … wordfence
3b8ea0b1-5050-43fc-8b80-b6a501a607fe
< 2.2
MEDIUM 6.1 The plugin Login/Signup Popup ( Inline Form + Woocommerce ) for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
3b89c9ce-086e-4b90-b469-97baae06b347
< 2.0.1
MEDIUM 6.1 The On Page SEO + Social Live Chat (Formerly OPS) plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… wordfence
3b8282a2-8265-4fa0-b137-6272b9e44fc3
< 0.9.5
MEDIUM 6.1 The W3 Total Cache plugin plugin for WordPress is vulnerable to Cross-Site Scripting via the 'request_id' parameter in v… wordfence
3b819e88-111a-4611-ae23-87ac7a878b4a MEDIUM 6.1 The WP Plugin Lister plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
3b791711-4028-4c22-837c-2837d2152d6d
< 3.4.3
MEDIUM 6.1 The WP2LEADS | WordPress und KlickTipp einfach verbinden – WooCommerce und KlickTipp einfach verbinden plugin for Wor… wordfence
3b739a4e-7cf2-46a9-8c75-939cdaa2e2c4 MEDIUM 6.1 The FastBook – Responsive Appointment Booking and Scheduling System plugin for WordPress is vulnerable to Reflected Cr… wordfence
3b705b50-4e8e-4ced-a74f-ef17b5440839 MEDIUM 6.1 The Essay Wizard (wpCRES) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
3b6e45ae-650e-45eb-b781-5acec1ba2dde
< 3.5.0
MEDIUM 6.1 The Kama Click Counter plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.4.… wordfence
3b5dc0af-90cf-41dd-a77b-4b99f267c0d9
< 1.6
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the user-login-history plugin through 1.5.2 for WordPress allow r… wordfence
3b59bf60-eadd-4942-a310-9d9f108820f0
< 26.8
MEDIUM 6.1 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Reflected Cross-Si… wordfence
3b4b2f0d-4803-4fcd-91c5-deca95037324 MEDIUM 6.1 The Email Attachment by Order Status & Products plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in … wordfence
3b3a2738-5312-4b34-9bd3-4ff95a91706e
< 4.29.9
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin 4.29.6 for Wor… wordfence
3b32a446-9100-4ce7-ba82-ec5e44b4520e MEDIUM 6.1 The Email on Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
3b0c6d8a-f673-4f04-92dc-88ccbc6ff9c9 MEDIUM 6.1 The DF Draggable plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
3b0336d7-1c85-4379-80db-19b478ba5471
< 1.5.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the new_Twitter_sign_button function in nextend-Twitter-connect.php in the N… wordfence
← Prev 951 952 953 954 955 956 957 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top