πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 973 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
27cfd3cd-e622-4be7-af47-84324d6f6ea3
< 4.2.1
MEDIUM 6.1 The Analytify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg witho… wordfence
27cf5b20-7a08-4d79-a9dc-9cd0072154e8
< 2.7.5
MEDIUM 6.1 The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable … wordfence
27bf9abc-b715-442e-9353-ec2154f658c1
< 2.5.1.9
MEDIUM 6.1 There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re… wordfence
27b79fe6-11b8-40bf-88e6-2a2b0fc41ed8
< 8.5.6
MEDIUM 6.1 The WP eStore plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'editproduct' parameter in al… wordfence
279f2c7f-385d-4ff4-bc10-ce8be7e217f9
< 1.5.0
MEDIUM 6.1 The Visionary Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
279a5460-25d1-4f80-8141-4d3af536258e
< 1.15.4
MEDIUM 6.1 The MultiParcels Shipping For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via sever… wordfence
279877c9-17e1-4caa-98a7-ecd43ff17ca1 MEDIUM 6.1 The Auphonic Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
278da117-fe04-45d6-86d4-e71fe6536032
< 4.7.34
MEDIUM 6.1 WordPress Core is vulnerable to Reflected Cross-Site Scripting via the 'log' parameter in all versions up to, and includ… wordfence
277ee4f8-4b13-4a58-a4ea-28f639ecea5e
< 1.5.6
MEDIUM 6.1 The User Role plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.5.5 due to … wordfence
277d09b6-cc2a-41db-8b2d-1bad8e49c0db MEDIUM 6.1 The Add Custom CSS and JS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
2766e8ee-ce19-40a9-8f53-d50ebe4f0ac9 MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the Media Library Categories plugin 1.1.1 for WordPress allow rem… wordfence
27574497-ca30-48ff-93ec-c430f5bfc689 MEDIUM 6.1 The Custom Page Extensions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
275268d6-5b08-441d-9924-3c99682b27d4
< 1.4.11
MEDIUM 6.1 The WP Search Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query… wordfence
272fd463-8e81-4041-9ab8-b2770d698a5f
< 1.04
MEDIUM 6.1 The Profile & Dashboard fields plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
2720ab1d-b5ac-4f52-b0bb-3f166877dd52 MEDIUM 6.1 The Spiritual Gifts Survey (and optional S.H.A.P.E survey) plugin for WordPress is vulnerable to Reflected Cross-Site Sc… wordfence
27205ad8-991f-4011-b1fd-759829acabd3
< 4.0.0
MEDIUM 6.1 The Essential Real Estate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
27153c13-6bdc-4873-8a05-8aab6ba4243d
< 1.1.3
MEDIUM 6.1 The WP Smart Import : Import any XML File to WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Script… wordfence
27142a35-99e7-4bac-9cfd-c0ab12886eef MEDIUM 6.1 The Easy Tynt plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2… wordfence
2713cd00-efd0-4a12-bf7b-2633289b3534
< 5.0.5
MEDIUM 6.1 The Shortcodes by United Themes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 5… wordfence
27051760-3c28-4e07-8c0f-2d054892da8f MEDIUM 6.1 The Slide Puzzle plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
26f8a133-c4a0-4c6c-a09e-47b81c65a731
< 5.2.8
MEDIUM 6.1 The 2Way VideoCalls and Random Chat - HTML5 Webcam Videochat WordPress plugin is vulnerable to Reflected Cross-Site Scri… wordfence
26f2b999-30cd-4427-9275-d6e21efb9630
< 2.3.8
MEDIUM 6.1 The Simple Payment plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
26ebbefa-01ff-48ca-be17-ca80e0de3b6c
< 3.8.7
MEDIUM 6.1 The Support Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 3.8.7 due to in… wordfence
26e52072-9465-4b56-9794-f17861b7c70c
< 2.3
MEDIUM 6.1 The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜id’ … wordfence
26d25f12-e7dd-4b30-859e-351aaaa9edff MEDIUM 6.1 The Shortcode in Comment plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
← Prev 970 971 972 973 974 975 976 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top