πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 969 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2cc5962f-4d3c-43ea-996b-a5bb3d0dccef
< 7.5
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and… wordfence
2cbd3bf0-6b20-41c2-8265-786dbba123d7
< 10.2
MEDIUM 6.1 The Cforms plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 10.1 due to insu… wordfence
2cbb586e-2438-4483-927d-07a7b63125a9
< 6.5.1
MEDIUM 6.1 The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wp_aff_referrer'… wordfence
2cae1194-2247-44bf-a1a0-0cb0068f56e0 MEDIUM 6.1 Reflected XSS in wordpress plugin e-search v1.0 via title_az parameter. wordfence
2c9f657b-82a5-40da-9e9a-95ea6f62d895
< 1.18.5
MEDIUM 6.1 The Gmedia Photo Gallery plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.18.5 due to ins… wordfence
2c96bfb8-290b-4818-a468-e8d5cb1850a3
< 2.1.14
MEDIUM 6.1 The MemberSpace – Membership Plugin and Paid Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
2c84781b-a866-40d3-8803-00cddf07c64a MEDIUM 6.1 The Grand News theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.4… wordfence
2c79caf2-1639-4ae3-b39b-2838db6febb0 MEDIUM 6.1 The User Session Synchronizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
2c76b38a-767c-44ab-af4b-ea69b9e37e4a MEDIUM 6.1 The Amazon Associate Filter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
2c677e0a-473f-4cc9-97f1-f2d57051f739 MEDIUM 6.1 The CRUDLab Google Plus Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
2c609a29-3c72-4921-ab7a-2f2593b2e4b4 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in vodpod-video-gallery/vodpod_gallery_thumbs.php in the Vodpod Video Gallery P… wordfence
2c5891b2-f919-4e86-9aa9-1eb56da14959
< 15.5.2
MEDIUM 6.1 The Simple Business Directory Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions u… wordfence
2c35a558-3915-4689-ab62-942792a93060
< 1.7.2
MEDIUM 6.1 The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all … wordfence
2c325190-a91d-4e80-8b01-edafeacb10a9 MEDIUM 6.1 The BuddyPress Greeting Message plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
2c1dbd73-6ea6-4e9d-84e2-055ab9db5f4f MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin 1.4.2.3 for W… wordfence
2bfa42f1-cb0e-4be9-91c8-573bffe332b5
< 2.3.7
MEDIUM 6.1 The Craft theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.3.6 du… wordfence
2bef9fbc-ada5-475d-b630-923483b8fb7a
< 1.10.1
MEDIUM 6.1 The Post Status Notifier Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $controller p… wordfence
2bc11785-6ec3-444f-9d06-0cc634429f9f MEDIUM 6.1 The Attach Gallery Posts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
2bbf5adc-df9c-4629-909c-932998c50508 MEDIUM 6.1 Reflected XSS in wordpress plugin tera-charts v1.0 via fn parameter. wordfence
2bbf4e86-308c-43f3-a54c-e1c6ee21260e MEDIUM 6.1 The Woocommerce Order address Print plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up … wordfence
2bafede8-9bd0-4c38-a402-42d419cc03fa
< 4.0.11
MEDIUM 6.1 The WPify Woo Czech plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
2badc91f-78de-4152-8207-699fc5c86935 MEDIUM 6.1 The Advanced Post Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
2baab094-5ece-41a2-821a-b594a2c2327e MEDIUM 6.1 The Grab & Save plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
2b9da491-771a-4100-b41a-7411981dd34b
< 1.1.7
MEDIUM 6.1 The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all … wordfence
2b959b65-16ad-45f9-9ad9-dfc97bda571e
< 5.8.3
MEDIUM 6.1 The Bonus for Woo plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_start' parameter in… wordfence
← Prev 966 967 968 969 970 971 972 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top