ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 957 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3f0b212a-969b-4cd3-a31c-40b9ff9dce5f
< 1.7.1
MEDIUM 6.1 The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via … wordfence
3f08fd6e-4c1b-40e7-92ba-72cdd03ff585
< 6.4b
MEDIUM 6.1 The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back… wordfence
3eff6af4-0553-4554-bce2-e355a4a06eec MEDIUM 6.1 The WooCommerce HTML5 Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
3ee49082-5255-4ab7-9562-bd786a32382c MEDIUM 6.1 The Turn off all comments WordPress plugin through 1.0 does not sanitise and escape the rows parameter before outputting… wordfence
3edce64d-13c2-454a-b5da-0454453f69cb
< 12.1.21
MEDIUM 6.1 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' and '… wordfence
3edc40b7-5cf6-413b-80c5-b001934bedc3 MEDIUM 6.1 The GNU-Mailman Integration WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the gm_error parameter … wordfence
3ed93cc1-66dd-414b-9c8c-5e0db44e1cf2 MEDIUM 6.1 The Migrate Posts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
3ed6d5e6-1094-46ec-afb9-43c142f334ed
< 1.3.4
MEDIUM 6.1 The Plausible Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page-url parameter … wordfence
3ed45d70-a528-47ee-84c9-26948dfe91f1
< 1.3.8
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in platinum_seo_pack.php in the Platinum SEO plugin before 1.3.8 for WordPress … wordfence
3ed1ab41-d4ad-4447-8914-f375b196d31b MEDIUM 6.1 The WpDevTool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
3ecdd962-7d85-4a60-956d-1e8a49507ab2
< 0.9.5
MEDIUM 6.1 The salavat counter Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter… wordfence
3ec48620-4969-43ff-bf42-72188dba001a MEDIUM 6.1 The Send to Twitter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
3ebebe75-155a-4097-95ec-f31c6047f19a MEDIUM 6.1 The Canva – Design beautiful blog graphics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all… wordfence
3eb4b3e7-6aad-4201-b48b-c8d788eb8acf
< 1.1.8
MEDIUM 6.1 The Limit Attempts by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catego… wordfence
3eab1e93-ecf1-4ac6-95b0-9a58c2de867a
< 1.7.9.1
MEDIUM 6.1 The Cooked plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.7.9 … wordfence
3e9bdb9d-bffe-4f6f-bb91-3dc5f7009f68 MEDIUM 6.1 The MultiSite Clone Duplicator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
3e8fe670-5072-43c2-8ff6-e8730d24b9cd MEDIUM 6.1 The Qiniu Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the swfupload.swf file in ve… wordfence
3e742b21-1097-459c-8c67-46d105e7b6e8
< 3.1
MEDIUM 6.1 The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in th… wordfence
3e6678db-6933-4a38-b704-214de7197852 MEDIUM 6.1 The Loginplus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.… wordfence
3e61c868-b430-4aa6-8664-ae237db73d66
< 1.1.47
MEDIUM 6.1 Cross-site scripting vulnerability in BackupGuard prior to version 1.1.47 allows an attacker to inject arbitrary web scr… wordfence
3e57ba2b-a95c-4410-9ba6-a66c6da36883 MEDIUM 6.1 The Premium WP Suite Easy Redirect Manager plugin 2.18.18 for WordPress has XSS via a crafted GET request that is mishan… wordfence
3e477f41-8765-472a-b48b-d381cf7de5c6 MEDIUM 6.1 The Photolio Theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerable versio… wordfence
3e471ef4-94c1-47d9-98ae-f79f7662e21a
< 4.3.1
MEDIUM 6.1 The Woocommerce Open Close – Best Business Schedules Manager plugin for WordPress is vulnerable to Reflected Cross-Sit… wordfence
3e46e6f4-c157-4d7a-8f50-f8c8213460fa MEDIUM 6.1 The ZoomSounds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.… wordfence
3e3c9f08-9e73-4791-b6ca-2c8b9dc3fb81
< 21.2.8.1
MEDIUM 6.1 The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress plugin … wordfence
← Prev 954 955 956 957 958 959 960 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top