πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 961 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
34e3ef09-9c6c-49c5-ac41-f9dc7662d5aa MEDIUM 6.1 The Popup Images plugin for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and o… wordfence
34d01610-0edc-488f-83e8-975206c0a02c
< 6.1.0
MEDIUM 6.1 The WooCommerce Predictive Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
34bae29d-4617-44c9-8f00-bd581cef4ab1
< 2.7.5
MEDIUM 6.1 The Appointment Calendar plugin for WordPress is vulnerable to Multiple Reflected Cross-Site Scripting via several param… wordfence
34ac0d3f-88ba-4b49-91af-e45f6b2ebf3a MEDIUM 6.1 The Js paper theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.5.7… wordfence
34a46c3a-22f9-4f61-844b-dd03c5208be7
< 2.3.7
MEDIUM 6.1 The Easy Digital Downloads (EDD) Recount Earnings extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x be… wordfence
349e3b4a-c46b-48f6-acf7-bcdc86c13db7
< 1.6.0
MEDIUM 6.1 The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view,… wordfence
349abf0b-fe0e-4dfb-b78d-811ee000d1e8 MEDIUM 6.1 The Simple Stripe Checkout plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
3497974d-cf58-4b38-a2c9-9bcd119ef43e
< 2.4.0
MEDIUM 6.1 The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_quer… wordfence
347573cf-037b-41e1-bebe-42c2a173068e MEDIUM 6.1 The Doofinder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.5… wordfence
347307eb-b5d3-45d8-962b-08e26b963d82 MEDIUM 6.1 The WP e-Commerce Style Email plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
34728e7a-2242-49fe-a11f-77258e302bab MEDIUM 6.1 Multiple cross-site request forgery (CSRF) vulnerabilities in the Bird Feeder plugin 1.2.3 for WordPress allow remote at… wordfence
346d9473-8738-4a06-9bb3-0a018a4d4974 MEDIUM 6.1 The WP Projects Portfolio with Client Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… wordfence
346cc9af-6a1b-444c-9483-94f940cd18ad MEDIUM 6.1 The Paramount theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versio… wordfence
3462a1b7-74d9-431a-b1c6-9960f1ad0c19
< 1.1.2
MEDIUM 6.1 The WooSidebars Sidebar Manager Converter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL… wordfence
3447c0ff-865c-4d94-9f33-a1824bf23794 MEDIUM 6.1 The Font Organizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'manage_font_id' parameter i… wordfence
343f5ad1-0507-48d8-8674-e4f811198daf MEDIUM 6.1 The NewsTicker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'news_ticker_id' parameter i… wordfence
343ef232-c0a7-4e08-a875-699c84c74ec2 MEDIUM 6.1 The Risk Warning Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
343e9aa9-b176-4c99-b2b4-04bd4bbf3c9b
< 2.4
MEDIUM 6.1 The Logtik theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.3 due… wordfence
343cf9a7-bc65-4e05-974b-66a94d2298e3 MEDIUM 6.1 The Easy Woocommerce Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
3438426a-c07d-4aeb-8272-2e13b70419a6
< 2.7
MEDIUM 6.1 The WPB Show Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'file' parameter in all v… wordfence
3436916c-a7ab-4960-8afe-145b3799392e
< 1.5.1
MEDIUM 6.1 The Clean Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
3428bc71-64f9-4f8d-85c8-7dda81b2ac18
< 1.0.22
MEDIUM 6.1 The Beam me up Scotty – Back to Top Button plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to… wordfence
341516d3-b785-4daf-98de-76f4f94b8c96
< 2.1.18
MEDIUM 6.1 The PDF Poster - PDF Embedder Plugin for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
340a46e5-b15d-4f0c-8b7e-51f7de7741b5 MEDIUM 6.1 The S3bubble Amazon S3 Media Streaming plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … wordfence
3408bdfd-6337-4c26-b0f2-377375d0e52c
< 4.15.23
MEDIUM 6.1 The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
← Prev 958 959 960 961 962 963 964 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top