πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 971 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2a4d8b76-8fb0-4239-ac4b-4ef4428be02b
< 3.8.12
MEDIUM 6.1 The Multivendor Marketplace Solution for WooCommerce plugin is vulnerable to Reflected Cross-Site Scripting via multiple… wordfence
2a3d8793-4b6a-4d57-a4cb-410a0e030a7a MEDIUM 6.1 The WP Post Modules for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
2a331f44-74d1-4481-98fb-27d3d983d8ea MEDIUM 6.1 The reCAPTCHA Jetpack plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
2a2b2a74-30d9-4e62-ab08-bbb2166e9a6b
< 4.3.3
MEDIUM 6.1 The SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payme… wordfence
2a17f466-bc4b-4668-8ff9-e8b316e3b5b7 MEDIUM 6.1 The rexCrawler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' and 'regex' parameters… wordfence
2a0f2774-4677-45a1-9c86-240a6e35f7af MEDIUM 6.1 The Product list Widget for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions… wordfence
2a0ce4fa-24d7-4c41-a003-999ff9f45a42
< 5.2.1
MEDIUM 6.1 The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API te… wordfence
2a0381b1-9b63-41cb-8125-d22274b98867
< 2.25.2
MEDIUM 6.1 The GiveWP plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.1. This is due to m… wordfence
2a001b31-042d-451b-ad9e-df8d41d3c2b0 MEDIUM 6.1 The Ajax Comment Form CST plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
29f21ad3-f2d9-48bf-99d6-fb80b8f3822f
< 1.4.8
MEDIUM 6.1 The Custom WP Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
29e3a20b-6b64-4eaf-93de-146a95d340c5
< 1.2.3
MEDIUM 6.1 The Reflector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2… wordfence
29d22612-8e0d-4275-b370-9729352c951e
< 2.0.60
MEDIUM 6.1 The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress i… wordfence
29c97617-78b1-4798-99a6-488176070e4a MEDIUM 6.1 The Bg Bible References plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
29b53c80-68d5-4431-a49b-0d139c9403f2 MEDIUM 6.1 The Marketing Performance Plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
299c4290-dc7e-44fb-887e-e3e53d3c070b
< 1.5.4
MEDIUM 6.1 The Shortcodes Finder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
298fa9e6-9487-4d3d-95de-5820a3761bdd MEDIUM 6.1 The WooMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 9.12 du… wordfence
298c6338-167f-499d-b4f2-852db2392b34 MEDIUM 6.1 The WPS Visitor Counter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
2987a5cf-4655-4d37-ae85-6f4775cc6802
< 1.5.5
MEDIUM 6.1 The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
297b9605-602f-458f-8b36-a184cdbd20df
< 1.0.5
MEDIUM 6.1 The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the UR… wordfence
295e67ef-0d68-4b76-8dab-54dc916f3569
< 3.2.3
MEDIUM 6.1 The Travel Booking WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions u… wordfence
29326ec5-edb7-44b7-bca9-21962037ccc8
< 1.10.15
MEDIUM 6.1 The WP24 Domain Check plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
29299b88-10fd-4c76-a8d7-34d8d4c7fd14 MEDIUM 6.1 The Cf7Save Extension plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
291c8df8-fd87-4554-b5e5-3d1f510dbfc2 MEDIUM 6.1 The Rename Author Slug plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
29125de3-eeed-4537-8915-e8100d2e65ca
< 1.0.9
MEDIUM 6.1 The Easy Digital Downloads (EDD) Per Product Emails extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x … wordfence
290233f0-a5dd-4c69-8039-7392268daf40
< 3.29.1
MEDIUM 6.1 The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via… wordfence
← Prev 968 969 970 971 972 973 974 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top