🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 958 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
38191721-8d5d-4a13-8271-c7ca96c3f6b8
< 2.2.9
MEDIUM 6.1 The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter be… wordfence
38145ad1-f441-40a4-9e92-6837cfeba656
< 2.3.6
MEDIUM 6.1 The EazyDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘edit_doc_one_page’ parameter… wordfence
3807d162-d62a-4370-b521-fba960a770ca MEDIUM 6.1 The WP-HideThat plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
38039171-f2cc-47d5-9b7b-d2c4a347a839 MEDIUM 6.1 The Tiger theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0 due … wordfence
3802cbf7-6725-4f93-a178-2af02bb022a1
< 3.7.30
MEDIUM 6.1 WordPress before 5.2.3 allows reflected XSS in the dashboard. wordfence
37f7edb2-4fc0-4785-a49d-6bae9aa57d42
< 1.3
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in wp-live.php in the WP Live.php module 1.2.1 for WordPress allows remote atta… wordfence
37f47ce1-0657-414d-a491-99f2722a44f5
< 1.3.25
MEDIUM 6.1 The BA Book Everything plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘date_from’ and … wordfence
37ea39bd-58c5-49f6-9956-8e0089e8192d
< 3.4.0
MEDIUM 6.1 The Official Integration for Billingo plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the us… wordfence
37e707ef-fe66-4c21-9c37-7b65fb7690db MEDIUM 6.1 The Easy Google Analytics for WordPress plugin is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
37d9171d-4722-4ebc-a773-9fd497bc12cf MEDIUM 6.1 The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Ref… wordfence
37cc54a9-a780-42b5-b64d-c47470f17db7
< 1.2.4
MEDIUM 6.1 The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily pla… wordfence
3798fb5d-f7d6-4a93-8908-c9b1f93bb05a
< 2.7.10
MEDIUM 6.1 The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escap… wordfence
378bc737-6547-4dc2-8123-3a33d7d2e122 MEDIUM 6.1 The Coronavirus (COVID-19) Outbreak Data Widgets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
377afb95-02d9-46b9-936d-3d58257dd928
< 2.2.0
MEDIUM 6.1 The Deliver via Shipos for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘d… wordfence
3779826a-90a4-4d6d-8387-2c8253985c64 MEDIUM 6.1 The SW Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2… wordfence
37563f9c-658c-4806-9bd8-a8413e7934fb
< 1.0.2
MEDIUM 6.1 The Workio theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filter-title’ parameter in v… wordfence
3742f2c5-55be-426c-8445-bf58eeebc74b
< 1.6.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Cakifo theme 1.x before 1.6.2 for WordPress allows remote authenticated … wordfence
3737d7a0-76d6-4292-aa31-6ee2cb0e9575
< 2.2.0
MEDIUM 6.1 The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to SQL Injection via the 'limit' variable in versions u… wordfence
372f4908-8796-4a52-8346-bd0eb1e41adc
< 4.0
MEDIUM 6.1 The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘td_video_url’ para… wordfence
372d1ff2-b56f-43ea-b4e6-fa09ddbbb1a9 MEDIUM 6.1 The Site Launcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
370e816c-920a-4e53-a2f8-afe2806c9df3
< 1.2.12
MEDIUM 6.1 The Fast Flow WordPress plugin is vulnerable to reflected Cross-Site scripting in versions up to, and including, 1.2.11,… wordfence
3708ce44-987f-4e73-b1cb-899349c8e0d4
< 1.0.9
MEDIUM 6.1 The Connector to CiviCRM with CiviMcRestFace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ver… wordfence
3704b365-cbdf-4c74-9619-59f0a10e3c6a MEDIUM 6.1 The Edit WooCommerce Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ p… wordfence
36f4e51d-d613-4db6-8d79-d26398c3e5df MEDIUM 6.1 Reflected XSS in wordpress plugin tidio-gallery v1.1 via galleryId parameter. wordfence
36ef164e-33cc-41b1-8e28-d2af89739f04
< 3.3.8.2
MEDIUM 6.1 The Watu Quiz for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'quiz_word_plural' parameter in vers… wordfence
← Prev 955 956 957 958 959 960 961 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top