🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 960 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
35d69a35-ec19-474a-a09b-0200bfa9e1db
< 3.0.3
MEDIUM 6.1 The Social Count Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
35d64d3e-b48e-4e35-ab1d-0557fcd62263
< 1.5.8
MEDIUM 6.1 The Smart Online Order for Clover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of… wordfence
35c7c089-6517-419e-8ba3-e6c2692fe1ae
< 4.0.4.6
MEDIUM 6.1 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Open Redirect in all vers… wordfence
35c608c3-9c28-4e0d-b0ec-d0a279fccd3b
< 1.7.1
MEDIUM 6.1 The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘_wpno… wordfence
35b6a26a-d7c1-4538-87f3-fcb1095797a3
< 2.1.9
MEDIUM 6.1 The wpForo Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wpforo_debug’ functio… wordfence
35b5a6ab-8909-49aa-8427-19355e6a7303
< 8.0.27
MEDIUM 6.1 The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page. wordfence
35b013c1-1574-4d5b-a3cb-e400ef7f2d32 MEDIUM 6.1 The H5P CSS Editor WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the h5p-css-file parameter found… wordfence
35a0f4dd-7370-48da-a4ef-424c42da60e9
< 1.0.1
MEDIUM 6.1 The Icons for Features plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_… wordfence
359e9b04-40a7-45f3-9d00-6fb3cd3463d9 MEDIUM 6.1 The KiotViet Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
359b8977-6d0d-4856-8d72-17091a420f67 MEDIUM 6.1 The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Cross-Site Scripting via an … wordfence
35896489-e48c-40f6-8815-9af759e58b44 MEDIUM 6.1 The Covert VideoPress Theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerab… wordfence
357bbb87-08f1-402d-a707-b69641099530 MEDIUM 6.1 The PeproDev CF7 Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i… wordfence
35790e70-6e96-4ffe-9d4e-828dd649e8c0
< 5.0.9
MEDIUM 6.1 The Product Table for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_k… wordfence
35707e4e-ca67-43fe-b120-79101ef31155
< 2.8.1.1
MEDIUM 6.1 The SMS for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
3563f70d-ab0a-48ec-9bb9-294b49026c1c MEDIUM 6.1 The spideranalyse WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the date parameter found in the ~… wordfence
35609838-3a36-46e5-8c51-23f3177e6449 MEDIUM 6.1 The Legull plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.… wordfence
3553044e-c109-4e6d-8ba1-f0d5cd1f72ef
< 1.7.5.6
MEDIUM 6.1 The Cooked Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
354c2c6c-5ba1-4bbe-88e4-9d219b66802a
< 2.6.7
MEDIUM 6.1 The Modula Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_quer… wordfence
3537ea8b-554b-4e41-902c-1d41b46deb1b MEDIUM 6.1 The Auto Repair theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 22… wordfence
35293a82-b535-47a2-8a34-e54fe836ca89
< 4.2
MEDIUM 6.1 The Jetpack plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the add_query_args() function in ve… wordfence
351c7d18-6c1b-4a52-98ae-478dee5aaff2
< 2.0.0
MEDIUM 6.1 The E-goi Smart Marketing SMS and Newsletters Forms plugin before 2.0.0 for WordPress has XSS via the admin/partials/cus… wordfence
3511f952-d816-4c70-9966-1ee61e281ef6 MEDIUM 6.1 The TS Comfort DB plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
34f7ab72-a4e3-4264-b6d3-530dd255dc87
< 1.1.2
MEDIUM 6.1 The Edit WooCommerce Templates plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includi… wordfence
34f260bd-8878-41ce-bdad-e4b60415e4f2 MEDIUM 6.1 The WP-Asambleas plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
34e62362-96cf-4779-8cb7-db5f7ed408d0 MEDIUM 6.1 The Post Sync plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
← Prev 957 958 959 960 961 962 963 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top