🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 964 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
31ff5e93-ed21-4c7b-a46e-3ca003b1f9d6
< 8.5.6
MEDIUM 6.1 The WP eStore plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'eStore_customer_search' para… wordfence
31f7dc1e-2008-4672-85ba-56fa35f4f0e1
< 6.5.3
MEDIUM 6.1 The WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in versions up … wordfence
31f72c5b-a99b-48a1-959b-9718b33139b4
< 2.6
MEDIUM 6.1 The WPB Show Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
31f5ddbf-2014-40e7-881d-27148bf133ff MEDIUM 6.1 The Easy Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in … wordfence
31ed0d2a-94bc-4526-9d21-6f2f544696d2
< 1.6.2
MEDIUM 6.1 The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'form… wordfence
31ecc794-b605-467b-8966-346846dc38de MEDIUM 6.1 The TabGarb Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… wordfence
31eb7dd4-3bd1-41e8-875a-e40a7f16296d
< 1.4.1
MEDIUM 6.1 The Post views Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'from’ and 'to' para… wordfence
31dcf302-9334-476c-a0e2-d8a31bcbbe5d
< 2.0.4
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Google Calendar Events plugin before 2.0.4 for WordPress allows remote a… wordfence
31db39a3-1b0b-4fdf-bef1-72308e38c9ff
< 1.9.64
MEDIUM 6.1 The UpdraftPlus free plugin before 1.9.64 (and UpdraftPlus paid before 2.9.64) are vulnerable to Cross-Site Scripting vi… wordfence
31cc700f-583e-4e7d-87b2-11998b505fb9
< 2.2.0
MEDIUM 6.1 The Tag Groups plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.… wordfence
31c6e07a-3a3a-4295-a86d-79b4ca1a331e
< 9.2.2
MEDIUM 6.1 The Newspaper theme for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 9.2.1 due to i… wordfence
31aa4f8b-954c-410e-9f18-c1e62dd9850b
< 3.1.25
MEDIUM 6.1 The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape t… wordfence
3199e007-2710-4eb7-acd0-e1645130f0a5 MEDIUM 6.1 The translit it! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
31801c90-4233-4ecf-837b-61513b65f8c9 MEDIUM 6.1 The Goodlayers Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
3172a459-8b3c-415c-97fc-ee5d248032c9 MEDIUM 6.1 The Simple Documentation plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
3155f8ba-b50e-490c-81bd-4a63142f164b
< 1.4.12
MEDIUM 6.1 wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unaut… wordfence
3137db18-6032-4ba5-9790-c1a7a95072b4
< 1.0.5
MEDIUM 6.1 The cp-polls plugin before 1.0.5 for WordPress has XSS via the 'name' parameter. wordfence
311cfaf3-f158-4936-a6a9-90b89469d75e MEDIUM 6.1 The WP Azure offload plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
311cc73c-9f5b-417c-8be9-c09ae70a64b2 MEDIUM 6.1 The Formulario de contacto SalesUp! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up … wordfence
311960e7-c4b4-4638-980f-1e08ffa621ba
< 5.0.12
MEDIUM 6.1 The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to DOM-… wordfence
310ffec4-cdd1-4e2e-a5f6-7e0ed5593dec MEDIUM 6.1 The CGD Arrange Terms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
310d9b83-6511-46be-aead-a0aa067d2c2f
< 1.1.3
MEDIUM 6.1 The Prostore theme for WordPress is vulnerable to Open Redirect in versions before 1.1.3. This is due to a lack of sanit… wordfence
310b09c6-6ab8-459c-8576-2fb9afc43dfd MEDIUM 6.1 The Fast Tube plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
3107fe1e-f997-4d13-9ecb-7fe9ff5a9c55 MEDIUM 6.1 The Viala theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3.1 du… wordfence
30f49721-13d6-4410-9dc5-6be69ada74a4 MEDIUM 6.1 The FP RSS Category Excluder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
← Prev 961 962 963 964 965 966 967 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top