🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 970 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2b818d20-8137-4e12-bc5a-325b6d213ebd MEDIUM 6.1 The Google Docs RSVP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
2b72bf37-05c8-424e-98d1-39fe032368ad
< 1.9.1
MEDIUM 6.1 The wassup plugin before 1.9.1 for WordPress has XSS via the Top stats widget or the wassupURI::add_siteurl method, a di… wordfence
2b6ffd9b-9a3a-4730-ab56-66686b24f214
< 1.2.0
MEDIUM 6.1 The Music Store – WordPress eCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all vers… wordfence
2b5ad113-f739-455a-9db6-b4f300b92837
< 5.16.5
MEDIUM 6.1 The Phlox PRO theme for WordPress is vulnerable to Reflected Cross-Site Scripting via search parameters in all versions … wordfence
2b58fb0f-c7ac-4ee6-84f1-ac14617a7c2b MEDIUM 6.1 The Zoorum Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
2b4e7c02-48d3-4271-a3bc-e7d3256b7217
< 1.4.5
MEDIUM 6.1 The LINE Notify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'uid' parameter in versions… wordfence
2b3b9576-7c7d-4665-92d5-03aa292cdbbe
< 1.7.0.11
MEDIUM 6.1 The Charitable plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
2b2fa832-ed1b-47e9-b9eb-049541530ab6
< 0.8.5
MEDIUM 6.1 The Blogroll Fun – Show Last Post and Last Update Time plugin for WordPress is vulnerable to Reflected Cross-Site Scri… wordfence
2b2302d9-426c-415b-a7d3-3a9de95d87d1
< 4.6.1
MEDIUM 6.1 The WPML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wp_lang parameter in versions up t… wordfence
2b1261d9-ab21-4ec2-84d7-f12a2013607a
< 1.0.4
MEDIUM 6.1 The My WP Translate plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.0.3 d… wordfence
2b107861-753e-4e47-98de-22a3e193e0c2 MEDIUM 6.1 The Famous - Responsive Image And Video Grid Gallery WordPress plugin for WordPress is vulnerable to Reflected Cross-Sit… wordfence
2b045cef-c17c-4e6e-ab84-c0466a5a90ff
< 2.6.16
MEDIUM 6.1 The Foliopress WYSIWYG plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the swfupload.swf file i… wordfence
2afa0d46-eead-4eb3-9bf1-81fafd3f0f88 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in js/test.php in the Appointments Scheduler plugin 1.5 and earlier for WordPre… wordfence
2ac0694e-6ec7-4e0a-bc7e-573df6a11ea3 MEDIUM 6.1 The Ultimate Subscribe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
2ab6f54d-0358-4f0c-aba5-b4053e1a345d MEDIUM 6.1 The BA Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up… wordfence
2aaa8c34-cf7b-4630-adc8-cbb534deff89
< 5.4
MEDIUM 6.1 The tagDiv Composer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
2aa84ea5-5e4e-4f1c-8238-c8ea0c70e248 MEDIUM 6.1 The WPHelpful plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2… wordfence
2a9a642f-1ca5-4f08-b404-c11deba100e9
< 2.4.2
MEDIUM 6.1 The gravity-forms-sms-notifications plugin before 2.4.2 for WordPress has XSS. wordfence
2a95122f-fe5a-43e4-a68c-8a6b96f0df2b MEDIUM 6.1 The Competition Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
2a896f57-e742-4eb6-85dc-c45d3f0747d8
< 11.12.08
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in uploadify/get_profile_avatar.php in the WP Symposium plugin before 11.12.08 … wordfence
2a8430ed-6aeb-46a3-8c42-59646845706e
< 0.9.33
MEDIUM 6.1 The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' paramete… wordfence
2a82666d-4c35-4aba-9163-834eef6c50ad
< 1.3
MEDIUM 6.1 The WP Crontrol for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up … wordfence
2a70ae7b-4b10-454b-8b28-b3d23d939cab
< 3.8
MEDIUM 6.1 The Gaea theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 3.8 due to insufficient i… wordfence
2a6d72d0-f262-46a1-91c7-1c34ab995614
< 4.5.0
MEDIUM 6.1 The Gallery by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’ p… wordfence
2a695233-01e3-4700-85a2-c4a9680e33db
< 1.4.8
MEDIUM 6.1 The WP Gravity Forms Salesforce plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including… wordfence
← Prev 967 968 969 970 971 972 973 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top