🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 956 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3a196177-2786-4f6d-8076-f0232e4d5a5d
< 1.0.16
MEDIUM 6.1 The Continuous Image Carousel With Lightbox for WordPress is vulnerable to Reflected Cross-Site Scripting via the search… wordfence
3a15516f-5492-4d9a-9cad-a4823a256f8d MEDIUM 6.1 The Lightview Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
3a12ae49-4e37-4302-8c91-60233e4912f5 MEDIUM 6.1 The Contexto plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … wordfence
3a0d85e8-33fa-46eb-b71b-d93715bc373e
< 4.3.44
MEDIUM 6.1 The WPtouch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without… wordfence
39e8c8e1-5bf4-4e4a-91a3-cf884cccf374
< 5.6.6
MEDIUM 6.1 The DeBounce Email Validator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'from', 'to', … wordfence
39e77def-8abe-4e62-ad99-a0c1d467aeb1
< 2.1.3
MEDIUM 6.1 The Mona Lisa theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘state’ parameter in versi… wordfence
39e58ba2-9eb7-4e39-b28b-31bb44b2ddc2 MEDIUM 6.1 The WP-NOTCAPTCHA plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
39e3fcf3-95f6-4844-b87a-5540041fe6a8 MEDIUM 6.1 The Very Simple Quiz plugin for WordPress is vulnerable to both Reflected and Stored Cross-Site Scripting via several pa… wordfence
39e10442-0a9e-4223-bb50-35b5d5ac8ff4 MEDIUM 6.1 The Easy Theme Options plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
39d69a5e-4265-4898-9fd8-736dc2297b91
< 1.1.8
MEDIUM 6.1 The HT Easy GA4 ( Google Analytics 4 ) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘[… wordfence
39c751c7-0480-4b92-bebb-a69114d79378 MEDIUM 6.1 The Easy CountDowner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
39ba2725-ecfb-49fd-9f7c-c4d606f48c73 MEDIUM 6.1 The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
39b8f6d8-bca2-4bf2-93ab-868270df8752 MEDIUM 6.1 The Download canvasio3D Light plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
39b728b9-8c9c-4965-8782-3f9b0d5bb8b1
< 1.1.5
MEDIUM 6.1 The WP Gravity Forms Dynamics CRM plugin for WordPress is vulnerable to Open Redirect in all versions up to, and includi… wordfence
39a74c20-42a2-4099-8e6c-9989a3ba081d
< 5.5.53
MEDIUM 6.1 The Salient theme for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.9 due to insuf… wordfence
399848fd-e9f6-40e4-bfeb-08f53eb511c6
< 3.1.6
MEDIUM 6.1 The EventPrime plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘event_id’ parameter in … wordfence
39843d5b-702d-466d-9e17-ccf1c4444220
< 1.3.16
MEDIUM 6.1 The Viper GuestBook plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.3.15 … wordfence
3974cd46-c55f-4930-abc0-75d36b49ce1e MEDIUM 6.1 The Send to a Friend Addon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
39719351-3388-4175-89a0-8ce153a8bf44 MEDIUM 6.1 The WooCommerce Payment Gateway Per Category WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a r… wordfence
396db2fd-d6be-449b-9719-0b4561e5afa8
< 6.8.9
MEDIUM 6.1 The Hoteller theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 6.8.9 due to insuffic… wordfence
395ff912-dad7-4dff-8bc4-bc58ecc96a90
< 1.1.5
MEDIUM 6.1 The Esplanade Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in version… wordfence
3956cd40-6b46-4013-9d71-a979de2c3687
< 1.1.10
MEDIUM 6.1 The Roles & Capabilities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_quer… wordfence
3947d20c-7e92-43d6-83cc-59efe1049799
< 3.1.17
MEDIUM 6.1 The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… wordfence
393b4e9e-4b2b-4c3d-baaa-bafc89cda382 MEDIUM 6.1 The Seo Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.… wordfence
3931b201-037d-4c4f-8e40-098c6c1251b9 MEDIUM 6.1 The Simple Page Transition plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$simple_page_tra… wordfence
← Prev 953 954 955 956 957 958 959 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top