πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 967 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2e8abe63-c11b-48e7-8867-3bc1ab940b1f
< 1.2.6
MEDIUM 6.1 Cross-site request forgery (CSRF) vulnerability in improved-user-search-in-backend.php in the backend in the Improved us… wordfence
2e895698-30dd-4703-b085-e9e7ad1ec1e1 MEDIUM 6.1 The Master Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
2e8527c0-a4b0-436d-901a-c07f93c7ec5e
< 1.0.49.47
MEDIUM 6.1 The Store credit / Gift cards for woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t… wordfence
2e7b6ef6-1238-4987-a7ad-dd19bb055b80 MEDIUM 6.1 The History timeline plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
2e7a78e1-8c1a-4fb4-9959-d8fb7f9ee917
< 4.20
MEDIUM 6.1 The Flexi - Guest Submit WordPress plugin before 4.20 does not sanitise and escape various parameters before outputting … wordfence
2e79b6b2-b227-44a4-85e3-6859c4f6f972 MEDIUM 6.1 The Tournamatch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4… wordfence
2e78bcfd-9764-49ae-9cac-cbc5419a0aa5
< 4.3.7
MEDIUM 6.1 The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Reflect… wordfence
2e6bd1d4-25ba-4475-8840-06f3d614d6d7 MEDIUM 6.1 The WP Smart Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
2e69254d-d9e4-4b9e-972e-30bb6de86776
< 4.1.8
MEDIUM 6.1 The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg. wordfence
2e680ed2-36a9-4ca4-8865-4ce58bf8f5d6
< 2.0.226
MEDIUM 6.1 The Contact Bank plugin for WordPress is vulnerable to Cross-Site Scripting via the 'form_id' parameter in versions befo… wordfence
2e62781e-4e35-479b-ad2f-617a679f180f
< 7.1
MEDIUM 6.1 The Pressroom - News Magazine WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in ver… wordfence
2e5b3595-932c-4a42-b340-f162b29f69ee MEDIUM 6.1 The Breezing Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
2e43b327-c141-480e-a5b2-bba179b3e0a1
< 7.2.9
MEDIUM 6.1 The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting… wordfence
2e405c91-e382-45d0-b01f-37774beeaf8b
< 1.4
MEDIUM 6.1 The Ultimate Classified Listings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… wordfence
2e2d54eb-c176-49c4-a4fc-833e17189cad
< 5.0.1
MEDIUM 6.1 The Matomo Analytics – Ethical Stats. Powerful Insights. plugin for WordPress is vulnerable to Reflected Cross-Site Sc… wordfence
2e268dfa-7761-4e52-9e97-288c58d2e5c3
< 1.5.4
MEDIUM 6.1 The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
2e1ca3b7-e402-40de-bed9-f443e3a7c952 MEDIUM 6.1 The Call To Action Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
2e11227f-87b0-42b2-98a5-555e49d983ad MEDIUM 6.1 The EmailShroud plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… wordfence
2e08e1b5-d388-46cf-a9e7-4bab2a09667f
< 1.5.35
MEDIUM 6.1 Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi… wordfence
2dee25f3-cbe2-4c30-97db-6cc90157c1a6 MEDIUM 6.1 The Contact Us By Lord Linus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
2db4a67d-0b54-4aa7-8d3a-b72fb3ad7f64 MEDIUM 6.1 The Schedule plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … wordfence
2db15abf-344c-45f1-927d-61ac2647f6be MEDIUM 6.1 The Map Contact plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3… wordfence
2da9c3d0-7efb-4c34-bf31-2f17a52c21f9 MEDIUM 6.1 The ultimate-weather plugin 1.0 for WordPress has XSS via the url parameter. wordfence
2da965b1-1f8d-4905-9711-bb9ad30f444a
< 1.6.65
MEDIUM 6.1 The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting… wordfence
2d9bf916-cdbf-410b-95bb-ca7ce6658e1b MEDIUM 6.1 The StudioZen Theme for WordPress is vulnerable to full path disclosure, content spoofing, and cross-site scripting in v… wordfence
← Prev 964 965 966 967 968 969 970 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top