🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 959 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
36dbe59e-b368-42f1-b72b-54123de43434 MEDIUM 6.1 The Partners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.2.… wordfence
36d9e9cd-7885-4127-b62c-ee0b3aad8846 MEDIUM 6.1 The Solidres plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameter in versions up t… wordfence
36d2fbbf-ea0e-4785-9b83-b642e59c713d
< 2.4.0
MEDIUM 6.1 The Freshdesk (official) plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.3.6… wordfence
36b2992d-4d1b-456d-94a0-54794ba59435
< 2.5.0
MEDIUM 6.1 The Radio Station plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
36ae359b-7694-4e8b-9fe6-5e9e40345305
< 2.4.0
MEDIUM 6.1 The WooCommerce Product Table Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘price… wordfence
36aaae54-5d26-4222-8511-d1eef6d8d0fe MEDIUM 6.1 The Solidres plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all vers… wordfence
3687a5ad-4666-49a5-8273-4159ec15756f MEDIUM 6.1 The WP Easy Poll plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
3674a90a-9844-40bd-a75d-3fed36dbc7cd MEDIUM 6.1 The Userpro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.1.9… wordfence
36741b46-57ac-402e-bfb1-8424c7e70598
< 3.1
MEDIUM 6.1 The Chaty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'channel' parameters in versions … wordfence
366165fe-93e5-49ab-b2e5-1de624f22286
< 4.3.9
MEDIUM 6.1 wordfence
365ec9c9-7bf4-4e5c-953e-58e3a7150cdb
< 1.4.4
MEDIUM 6.1 A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been rated as problematic. Affected by this … wordfence
365808af-5ed1-4265-88bd-ca8a49bdf424 MEDIUM 6.1 The Kanban Boards for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
36510335-df4c-473d-8091-ba7e070525bf MEDIUM 6.1 The Ni WooCommerce Order Export plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
364d6bd8-cdb8-4c99-b610-ba9a3125909e MEDIUM 6.1 The SH Contextual Help plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
364c8488-dab2-46bd-84b6-adfa59e2b013
< 1.6.8
MEDIUM 6.1 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all ve… wordfence
364a9a12-d6d4-4461-b45f-cf7d6ea815ac
< 2.5.6
MEDIUM 6.1 The Reality | Estate Multipurpose WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting vi… wordfence
364946a5-ce1e-4872-895d-e7cf795a04f7
< 3.2.1
MEDIUM 6.1 The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pag… wordfence
363ece80-1fa6-4019-84c9-e0a65f02625d
< 2.1.0.12
MEDIUM 6.1 The WP Inventory Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘message’ para… wordfence
363abb15-2169-41c1-87cb-7f3e90cea394 MEDIUM 6.1 The Custom Coming Soon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
362fcd02-73c3-413b-8076-694c4d55544d
< 1.66
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the RedLine theme before 1.66 for WordPress allows remote attackers to injec… wordfence
360fee18-5b5c-4aef-958b-915691e939bc MEDIUM 6.1 The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versio… wordfence
360cb170-a888-4b7f-8ea2-1d74a404f1df
< 1.2.17.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in index.php in the Unnamed theme before 1.2.17.1, and Special Edition (SE) 1.0… wordfence
35fb04aa-5899-4797-9ea1-24e7a98ad8d3
< 2.2.7
MEDIUM 6.1 The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back i… wordfence
35f9f778-b056-4188-b34f-3c45b91a0138
< 8.8.00.003
MEDIUM 6.1 The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
35f49283-00e5-450e-a908-261b0357b36b
< 1.8.6
MEDIUM 6.1 The W3P SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.5… wordfence
← Prev 956 957 958 959 960 961 962 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top