ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 955 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3ae9392a-591c-4be0-9f90-aa6ec81d3a10
< 1.8.4.7
MEDIUM 6.1 The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scr… wordfence
3adfbfcc-5d52-4a01-805d-c3273757aba1 MEDIUM 6.1 The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Reflected Cross-Site Scri… wordfence
3ad2e495-5181-44a7-932f-520620146be7 MEDIUM 6.1 The World Prayer Time plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
3acc1464-18cf-4085-8cb4-946563d70b16
< 2.8
MEDIUM 6.1 The WP Page Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘taxonomy’ parameter… wordfence
3ac577f4-2e61-4b72-881e-6fbbfd268f7b MEDIUM 6.1 The Elementor Forms Google Sheet Connector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … wordfence
3abde27c-8234-4146-9e55-ea20b275ca48
< 2.5.2
MEDIUM 6.1 The New User Approve plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
3aa73be6-0836-4540-8a80-e1da34c0ee0d MEDIUM 6.1 The Shabat Keeper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] para… wordfence
3aa56fc7-8d48-4149-afa7-8f9885de0674
< 1.4.2
MEDIUM 6.1 The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘x1’ parameter in all vers… wordfence
3aa14f56-85b7-4f8d-bc62-a1e99977e510
< 1.1.14
MEDIUM 6.1 The Travelpayouts: All Travel Brands in One Place plugin for WordPress is vulnerable to Reflected Cross-Site Scripting i… wordfence
3a92926f-c8d2-49c4-b50e-2544fd66fe01
< 1.8.3
MEDIUM 6.1 The Amazon Affiliate Link Localizer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and in… wordfence
3a9045e5-ee8b-45f6-8e08-b1bf6b6f7159
< 1.3.15
MEDIUM 6.1 The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to… wordfence
3a8998db-ffc2-40b2-a191-09380984adac
< 2.8.4
MEDIUM 6.1 The Social Media & Share Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown param… wordfence
3a849ef2-ad0a-45ea-8827-9a7233b1ca30
< 1.0.99
MEDIUM 6.1 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Reflected Cross-Site S… wordfence
3a7afe2c-13ca-4df4-89c9-1544db016cdc
< 4.2
MEDIUM 6.1 The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back … wordfence
3a7aac7d-225f-45d5-86ac-183c56e76326
< 5.4.31
MEDIUM 6.1 The Woffice theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.4.30… wordfence
3a6eac3b-823a-4a26-acb7-339357c10a07
< 1.7.6
MEDIUM 6.1 The "Htaccess by BestWebSoft – WordPress Website Access Control Plugin" plugin for WordPress is vulnerable to Reflecte… wordfence
3a69bb27-dc93-4515-90e1-08a1fa5fdaa0
< 2.0.9
MEDIUM 6.1 The Magee Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in vers… wordfence
3a66d49d-eb3a-4ba3-bf2e-deeb7f5c197b
< 1.1.3
MEDIUM 6.1 The Analytics Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
3a5e8af3-fa65-4703-8f34-a48b102ec084 MEDIUM 6.1 The ECT Home Page Products plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
3a503925-7fbf-42e8-9cee-604858c8ec0c MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in forms/search.php in the WP-Business Directory (wp-ttisbdir) plugi… wordfence
3a4f0c06-db88-4950-b1f5-b2aab480c974
< 8.8.07.004
MEDIUM 6.1 The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' paramete… wordfence
3a48c501-6fa6-4767-b3f0-6b15e56807d9 MEDIUM 6.1 The AppReview plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.2… wordfence
3a468814-ecb7-4414-9472-6c2aaa5f5c2c
< 9.0.28
MEDIUM 6.1 The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST … wordfence
3a2c96a1-bbab-41ed-aafd-6a6f569242f3
< 2.19.2
MEDIUM 6.1 The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter … wordfence
3a28f29e-7831-4a61-b5d1-d34d09b0e830
< 1.0.61
MEDIUM 6.1 The Captcha.eu plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
← Prev 952 953 954 955 956 957 958 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top