🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 972 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
28fd9f64-4451-46fd-bdeb-cc5a538ea563
< 1.12.05
MEDIUM 6.1 The xili-tidy-tags plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in al… wordfence
28f77d5a-fc17-4e17-85b9-4e6f66dbf2c7
< 2.1.20
MEDIUM 6.1 The GTM Server Side plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg… wordfence
28f08640-cd63-4f2a-a785-1956dc051991 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in index.php in the Sirius 1.0 theme for WordPress allows remote attackers to i… wordfence
28d8ebf9-2841-4a54-8537-959c43ca88e4
< 2.6.4
MEDIUM 6.1 The Perfmatters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2… wordfence
28d41721-c538-4043-a411-3234ff1074bc
< 0.9.2
MEDIUM 6.1 The Send PDF for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includ… wordfence
28c8abf2-09e2-43a2-8666-ca2a896bdbbe
< 1.6.8
MEDIUM 6.1 The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in t… wordfence
28a9c2ba-7667-4601-8808-7258af69a432
< 3.6.19
MEDIUM 6.1 The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
28928a78-24c2-44d2-a9e4-33c2f352d089
< 1.3.8
MEDIUM 6.1 Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an at… wordfence
2890a126-2752-4695-9eb6-a360c9bf69bb MEDIUM 6.1 The TinyMCE Advanced qTranslate fix editor problems plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
288fdb71-1dae-4897-b5af-95c628fce288
< 1.0.31
MEDIUM 6.1 The plugin in versions up to 1.0.30 does not sanitise or escape its tab parameter in the Settings page before outputting… wordfence
288db6ba-5d6c-448d-85c5-f9a19a9391c0 MEDIUM 6.1 The Login Screen Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
2889ac63-6644-436d-9805-1efc9048d69c MEDIUM 6.1 The School Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
287d02ba-9cf0-446a-9393-036bd42b7aef
< 1.2
MEDIUM 6.1 The Tock Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
286e52b4-2694-4f3b-9d1d-fd1ebf1d1e50
< 2.1.0
MEDIUM 6.1 The Tiger Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the use of PHP_SELF in versions… wordfence
28524702-3428-4fca-afe8-71b3f2dd983d
< 4.2.9
MEDIUM 6.1 The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm… wordfence
28456329-03f3-4c33-92f5-e4076aa15345
< 1.5
MEDIUM 6.1 The Comment Reply Email plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
282ef0bb-4db5-4b07-9aad-b128e8fdb915 MEDIUM 6.1 The User Email Verification for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in vers… wordfence
28267144-a709-4631-8925-69c6e0aca77c
< 1.6.1
MEDIUM 6.1 The Additional Custom Order Status for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
2822114a-ffc2-43dd-bbf1-e4504aababfb
< 2.2.2
MEDIUM 6.1 WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive i… wordfence
281c49d3-078a-4fdc-9720-dac6b3a32892
< 1.5.3
MEDIUM 6.1 The Shortlink by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’… wordfence
2809d55f-14f8-4916-800f-4d4fb9ee88c0 MEDIUM 6.1 The WP Songbook WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the url parameter found in the ~/in… wordfence
28066511-a1e3-498d-a462-5e868334bfe1 MEDIUM 6.1 The International Sms For Contact Form 7 Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
2805267e-fd07-4bb2-b2e5-7c90c667097e MEDIUM 6.1 The Simple Image Gallery WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in… wordfence
27ec8f97-9b34-4737-bb45-37baf59598f1
< 2.2.4.1
MEDIUM 6.1 Cross-site scripting vulnerability in Open Graph for Facebook, Google+ and Twitter Card Tags plugin prior to version 2.2… wordfence
27e0b9e8-b6b7-45fe-8c9e-5e49c4feccac
< 3.1.2
MEDIUM 6.1 The Sunshine Photo Cart plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
← Prev 969 970 971 972 973 974 975 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top