🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 965 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
30edc2a1-f3fe-488d-a525-f0ae3482d8a8
< 1.5.4
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in pretty-bar.php in Pretty Link Lite plugin before 1.5.4 for WordPress allows … wordfence
30dda650-3262-4d22-bec7-b6de3bc25381
< 1.3.11
MEDIUM 6.1 Multiple cross-site request forgery (CSRF) vulnerabilities in the WP-ViperGB plugin before 1.3.11 for WordPress allow re… wordfence
30c0118c-3dae-4d76-8e9f-ea747d44a788
< 2.9.4
MEDIUM 6.1 The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter befo… wordfence
30badf18-f54f-40a0-b5b0-e8d49f1f1828
< 1.1.5
MEDIUM 6.1 The WATI Chat and Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
30b4b98e-c566-4249-85a4-bfb0b5d5ac5d MEDIUM 6.1 The Finalist Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all vers… wordfence
30a6453b-a31e-4cec-a531-9a3dd3053277 MEDIUM 6.1 The WP Frontend Submit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
306facf0-b1e4-4ba7-9462-f94af01d628d
< 4.4.7
MEDIUM 6.1 Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versio… wordfence
305f9e72-3a3f-4b22-8097-f37b1a1ebe1d
< 2.5.4
MEDIUM 6.1 The "BestWebSoft's Like & Share – Posts, Pages and Widget Social Extension plugin for WordPress" plugin for WordPress … wordfence
305f2f13-178d-4b49-b59b-abb35d111299
< 1.2.5
MEDIUM 6.1 The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
304b0b69-90bc-416e-9d76-82b176a9de34
< 1.10.2
MEDIUM 6.1 The FraudLabs Pro SMS Verification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
30430993-b5bc-42fb-9968-7a372b2285c8
< 2.4.6
MEDIUM 6.1 The Feedify – Web Push Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … wordfence
303f348b-846c-4aad-9193-36e056a02f71 MEDIUM 6.1 The LH Login Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
30319b65-f111-4637-97df-ceb831d5fa3c MEDIUM 6.1 The Easy Language Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
302e80da-8a7e-4883-8e0f-658fff2579bd MEDIUM 6.1 The LocalGrid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0… wordfence
3011f85c-fa30-4ccf-b067-dba45e491acb
< 2.0.5
MEDIUM 6.1 The WordPress Comments Import & Export plugin for WordPress is vulnerable to CSV Injection in versions up to, and includ… wordfence
3003bd3b-aee5-4bac-9a62-e747f544d2bd
< 4.6
MEDIUM 6.1 The Dave's WordPress Live Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ … wordfence
2ff83bf5-369f-43b9-b073-daf0de9051c7
< 3.2.5
MEDIUM 6.1 The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
2fef8861-e992-474b-b006-ebb3cb8e4cf4 MEDIUM 6.1 The Ahmeti Wp Timeline plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
2feabc97-0463-4e50-91a8-234445ca2504
< 2.9.24
MEDIUM 6.1 The PowerPack Pro for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
2fe34989-493c-4883-a1ca-454262919202
< 2.1
MEDIUM 6.1 The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0… wordfence
2fcbd6c5-dd03-439c-b6b8-54b0c24a1c27
< 1.3.1
MEDIUM 6.1 The WordPress Super Cache Plugin 1.3 has XSS via several vulnerable parameters. wordfence
2fbeee6b-cbc0-462e-96ba-2fd4f54786b0 MEDIUM 6.1 The Fotomoto plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_id’ parameter in ver… wordfence
2f9a3883-9755-4de8-9d60-113238b3c0ac MEDIUM 6.1 The Simply Exclude plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all … wordfence
2f7ddb34-cb5b-4089-bd3e-07056f0b6bd5
< 1.7.10
MEDIUM 6.1 The Yotpo: Product & Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
2f7c1848-d49f-4f34-8869-3ddbdccdc38f
< 2.1.3
MEDIUM 6.1 Cross-Site Scripting (XSS) vulnerability in WP Wham's Checkout Files Upload for WooCommerce plugin <= 2.1.2 at WordPress… wordfence
← Prev 962 963 964 965 966 967 968 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top