🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 963 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
32f03892-500f-4925-9b3d-3160243de8a0
< 3.3.9
MEDIUM 6.1 The Simple Download Monitor plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including,… wordfence
32eb02b8-71cd-4cdb-aa9d-3fd1850fb126
< 2.4.8
MEDIUM 6.1 The WP2Social Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all v… wordfence
32deb3f1-a2dc-4a75-82be-21b90dc4ec11 MEDIUM 6.1 The GeoDigs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3… wordfence
32dd8dd7-d08a-444d-a76d-984ab25cc42c MEDIUM 6.1 The ThemeFuse Maintenance Mode plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
32d4c259-b56d-4f8f-84b8-7ef451fd02ad
< 2.11.8
MEDIUM 6.1 The Tourfic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.11.… wordfence
32c805a7-5818-442e-bc49-661b0d3320e8 MEDIUM 6.1 The EC Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
32c46940-d396-4b2a-9f1c-1ca51b8d16a9
< 1.5.0
MEDIUM 6.1 The WooCommerce Report plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
32add0cc-445e-4039-9dfa-15f154b4d7c6 MEDIUM 6.1 The wireless-butler theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
32ac72f7-6bcc-4b5d-925a-9c5fc0c1f065
< 1.17.4
MEDIUM 6.1 The Advanced Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘advads-last-edited-grou… wordfence
328c2df0-e8e9-46e8-a95d-d0b65f9d2f0b
< 1.22.26
MEDIUM 6.1 The Team Showcase plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
328b6de6-e003-470d-ae03-28c9bdb617e0 MEDIUM 6.1 The Evangelische Termine plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
3285f4ee-086f-4111-b5d9-d37e269aa2ad MEDIUM 6.1 The Password only login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
3280c728-c71d-417a-a188-40dad3cd5996 MEDIUM 6.1 The User Messages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'filter_type' parameter i… wordfence
326707a9-5d37-4d26-a9d4-3b2db84289b9 MEDIUM 6.1 The Opencart Product in WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
32648d65-88a7-48fa-adeb-3060a1cf5b93
< 2.7.27
MEDIUM 6.1 The Unyson plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘extension name’ parameter … wordfence
325c2350-174b-4117-bacd-ae28bf3b16bc MEDIUM 6.1 The SEO Keywords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘google_error’ paramet… wordfence
3253e1b3-ac63-4796-ac10-92781d5a76c8
< 3.1.12
MEDIUM 6.1 The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p… wordfence
324e5681-a76f-4611-adff-02b4735f4efc
< 1.8.5
MEDIUM 6.1 The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
324a51af-587e-4831-a48e-13bbd5038fc7
< 2.7.9
MEDIUM 6.1 The SportsPress WordPress plugin before 2.7.9 does not sanitise and escape its match_day parameter before outputting bac… wordfence
324448a3-759d-462b-bf38-64414d134228 MEDIUM 6.1 The UberSlider MouseInteraction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
323fde5c-5b63-462d-ae8b-8414ef0f36f3 MEDIUM 6.1 The flashy theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.1 d… wordfence
32385e77-9629-4aa2-8f1e-9804809fcea3
< 3.9.8
MEDIUM 6.1 The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature. wordfence
32348f79-232f-42e6-bbea-aba6203d9f26
< 4.36.0
MEDIUM 6.1 The Web Push Notifications – Webpushr plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p'… wordfence
32253923-ffec-4312-bcdf-06c5aed77d30
< 1.5.1
MEDIUM 6.1 Multiple themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the search field in various versions … wordfence
32237c21-2fec-4228-8264-e9f3f1a70060
< 3.0.6
MEDIUM 6.1 The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it … wordfence
← Prev 960 961 962 963 964 965 966 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top