🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 968 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2d8fdeee-5970-45bb-b29c-c102d46c17ac MEDIUM 6.1 The ATT YouTube Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
2d8a619c-d805-49fe-ad6c-a2fd216be84e MEDIUM 6.1 The WP OpenSearch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
2d8585df-f933-4bd6-a157-56a51d4f8a4a
< 3.1.3
MEDIUM 6.1 The Adsmonetizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all ve… wordfence
2d7ee078-e9b1-4583-9b07-03fbf4034859
< 3.6.4
MEDIUM 6.1 The lbg-audio5-html5-shoutcast-sticky plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versio… wordfence
2d7ea482-c45e-4a73-9e64-4d4438e197b4
< 1.2.7
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the EvoLve theme before 1.2.7 for WordPress allows remote attackers to injec… wordfence
2d79ad4c-6b7e-4bf9-93af-76b8c3599d47 MEDIUM 6.1 The Dialogs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dialog_id’ parameter in ve… wordfence
2d7264bc-7fa1-4f5f-a8bc-0840374b7a08
< 0.6.69
MEDIUM 6.1 The Adaptive Images plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘REQUEST_URI’ in ve… wordfence
2d6cf33c-ac40-4892-9345-64ebe61e6be6
< 6.3.1
MEDIUM 6.1 The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Sc… wordfence
2d60ea41-c103-4b56-a920-d4b82698d630
< 5.22
MEDIUM 6.1 The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
2d5fb4ac-f86e-4b5e-ad4b-be19158ab745
< 1.24
MEDIUM 6.1 The Stop Registration Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
2d59e599-59da-4c03-b71f-d00a078b2442
< 3.4.9.6
MEDIUM 6.1 The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of … wordfence
2d540b53-5c39-43d5-a055-cc5eccfa65b8
< 1.7.22
MEDIUM 6.1 The WordPress WP YouTube Live Plugin is vulnerable to Reflected Cross-Site Scripting via POST data found in the ~/inc/ad… wordfence
2d3ca386-0bec-48fb-963f-03b236c94308
< 1.4.8
MEDIUM 6.1 The theMarketer – Email marketing, Newsletters, Automation & Loyalty for Woocommerce plugin for WordPress is vulnerabl… wordfence
2d390a7e-f790-4953-b3cb-be31cfec6fb0
< 1.9.5
MEDIUM 6.1 The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back… wordfence
2d248c0e-9990-4107-996a-a65baab25cb0 MEDIUM 6.1 The Advance WP Query Search Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up t… wordfence
2d22f0e0-2f5d-496f-88c1-cdbec0318cfd
< 1.3.6
MEDIUM 6.1 The WPYog Documents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
2d0401b3-2308-49d5-9e94-23dafb46297e MEDIUM 6.1 The LeaderBoard Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
2d038687-59ba-4183-96ab-fd9fd0dcf26f
< 1.2.1
MEDIUM 6.1 The Term Taxonomy Converter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
2d010e55-d57a-49f7-a991-76b676b88f1e
< 5.2.4.2
MEDIUM 6.1 The RegistrationMagic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘section_id’ para… wordfence
2ceaa52e-564d-4454-8e3b-dc6899c910dd
< 3.2.5
MEDIUM 6.1 The Houzez theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.2… wordfence
2ce60724-3ef8-4222-9034-88edb8a4ce0e
< 1.0.6
MEDIUM 6.1 The NewStatPress plugin before 1.0.6 for WordPress has XSS related to an IMG element. wordfence
2cda7499-2275-4d86-949f-1bc38fcdaee3 MEDIUM 6.1 The Easy Social plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
2cd7d8ee-5947-4317-b872-0b5ee829ad0d
< 1.3
MEDIUM 6.1 The Tribulant Gallery Voting plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
2cd6e69b-f927-4cea-a838-5c73f52233a2
< 1.24.8.19
MEDIUM 6.1 The SendPress Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter … wordfence
2cce2a10-3d5f-4249-9085-923a1fa76385
< 1.0.8.8
MEDIUM 6.1 The Goya theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attra-color’, 'attra-size', a… wordfence
← Prev 965 966 967 968 969 970 971 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top