πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 962 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
34045b62-a4d8-4fa0-ac8b-e1ca8ca72fca
< 1.05
MEDIUM 6.1 The API info for Plugins & Themes from WP.ORG plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ve… wordfence
33fd4542-0a46-4779-be02-d713dcbc8f96 MEDIUM 6.1 The WCP Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜tab’ parameter in… wordfence
33e5ca87-2e45-4b85-818e-02093bbf66ee MEDIUM 6.1 The jLayer Parallax Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
33dcaf9b-4c4b-4c8a-a0b7-fa44b64525a3 MEDIUM 6.1 The Bible Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0… wordfence
33cfebae-bbf3-4b0b-9afc-3ef2548045e7 MEDIUM 6.1 The Zen Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
33a26790-1fb8-4088-87dc-e026a28f205d
< 0.0.6.6
MEDIUM 6.1 The Encrypted Blog plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 0.0.6.2 via the… wordfence
338d35a8-5733-4ecd-baa7-246dfb24718f MEDIUM 6.1 The Glossy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'gs_edit_entry' parameter in all… wordfence
338be12e-f5d9-4697-a409-428188d222f8 MEDIUM 6.1 The Milat jQuery Automatic Popup plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
33836cee-c3f6-4c49-9acb-7c8f00839fdd
< 1.0.7
MEDIUM 6.1 The Easy Digital Downloads (EDD) Favorites extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.… wordfence
3379ba15-b834-431d-a1ef-ba811df5da58 MEDIUM 6.1 The melascrivi-plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
33707b80-5cc1-4678-bf87-8c5131634c94
< 3.9.3
MEDIUM 6.1 The Video Conferencing with Zoom plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of … wordfence
3363149f-a522-49a1-94c8-a3bcd865f911
< 4.11.9
MEDIUM 6.1 The Table Rate Shipping Method for WooCommerce by Flexible Shipping plugin for WordPress is vulnerable to Reflected Cros… wordfence
3362e70b-1c0e-4faa-9607-88cb805da2c6 MEDIUM 6.1 The WordPress Galleria plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
335960e7-a0fa-4f36-9b06-a77b6273b070
< 4.23.9
MEDIUM 6.1 The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Refl… wordfence
3357892e-c047-406b-8914-018ea966e799
< 2.16.3
MEDIUM 6.1 The Currency Switcher for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the us… wordfence
33512495-91d6-4efe-9c76-484ab07874f6
< 3.9
MEDIUM 6.1 The plugin Easy Testimonials for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a… wordfence
334fb374-c84b-4fec-8653-f7ad6af1f631 MEDIUM 6.1 The WP-Ultimate-Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
3346d686-fc31-4d5f-925b-e059fadb3fe6 MEDIUM 6.1 The Spoiler Block plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
332b8d96-89b2-473b-9186-239e49f5b064
< 3.2.54
MEDIUM 6.1 The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['RE… wordfence
3323b809-b778-48fb-967c-cedba9010495
< 5.8.1
MEDIUM 6.1 The YOP Poll plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.8.… wordfence
331fd693-25be-4163-a415-73d1cbcee5a8 MEDIUM 6.1 The Browser-Update-Notify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
33153ebe-65fc-4db8-84fe-df22554be3ba
< 0.5.2
MEDIUM 6.1 The check-email plugin before 0.5.2 for WordPress has XSS via several vulnerable parameters in the check-email/check-ema… wordfence
3313f919-5fa8-4e2f-b676-b5654d088e33
< 3.6.1
MEDIUM 6.1 The WP Coder – Code Snippets + HTML, CSS, JS and PHP Injection plugin for WordPress is vulnerable to Cross-Site Reques… wordfence
33074011-595a-4218-84e8-e28b75c12815 MEDIUM 6.1 The Twitter News Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
3302cb58-e5d7-4c15-9f2d-f8951c32451e
< 3.25.18
MEDIUM 6.1 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
← Prev 959 960 961 962 963 964 965 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top