πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 975 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
25a9fd76-15aa-43f9-bb11-9825b847a4e3
< 2.3.1
MEDIUM 6.1 The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ve… wordfence
259f9ea3-ac24-4bea-8d0d-c635a68d9c98
< 2.35.20
MEDIUM 6.1 The 404 Solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, an… wordfence
259f2e45-23df-442a-abb5-d37aadf7f045
< 4.2.6
MEDIUM 6.1 The Contact Form With Shortcode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up … wordfence
2598ae85-5e91-47e6-b3f5-0d977fe80dd5
< 2021.9
MEDIUM 6.1 The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a sp… wordfence
2598076e-85d6-40a7-a975-36c3f7320c4f MEDIUM 6.1 The WS Audio Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
25838724-42b6-41e1-9546-78e6da2e95e1
< 2.1.8
MEDIUM 6.1 The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not prope… wordfence
257aba03-bb41-4798-b62c-b51310d70264
< 0.8.21
MEDIUM 6.1 The Chatbot with IBM Watson plugin before 0.8.21 for WordPress has a DOM-based XSS vulnerability that is executed when a… wordfence
2578a863-4129-4f56-8b18-65b2d2b972e3
< 4.9.9.8
MEDIUM 6.1 The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "to" parameter in all versi… wordfence
25762427-8d31-4fef-8b93-1065d15cd918
< 2.1.13
MEDIUM 6.1 The Slideshow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up… wordfence
256be233-e950-4a93-8153-83a297b0d4ca MEDIUM 6.1 The Block Controller plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
2568d209-a89d-495d-adc1-c44aef75d337 MEDIUM 6.1 The Push Envoy Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
255f0fc4-5023-4039-9418-2f28363dbfc4
< 0.9.56
MEDIUM 6.1 The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … wordfence
255e7322-641a-4b05-ae2d-0ec90d133e8e
< 1.1.5.6
MEDIUM 6.1 The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1.5.… wordfence
255a50f0-0213-4de5-92f1-d71dbb5caeff
< 3.2.2
MEDIUM 6.1 The Nimble Page Builder WordPress plugin before 3.2.2 does not sanitise and escape the preview-level-guid parameter befo… wordfence
25595c99-87e2-408d-9931-c864af1cedd8 MEDIUM 6.1 The MHR-Custom-Anti-Copy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
2549394c-2f2f-4d90-a11c-ba6f28c3ea39 MEDIUM 6.1 The Video Blogster Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
2546ea7e-133a-44b8-9cdb-1b345a45d583
< 2.1.9
MEDIUM 6.1 The WP Crowdfunding plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all ve… wordfence
253dcecb-b88d-423c-8e74-1d59581e2893
< 5.9
MEDIUM 6.1 The Library Bookshelves plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query… wordfence
252c616f-2198-43d7-8767-3704f192a391
< 25.0513
MEDIUM 6.1 The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
25250755-0d22-44f4-8930-3a60efd61e32 MEDIUM 6.1 The Truemag theme 2016 Q2 for WordPress has XSS via the s parameter. wordfence
2523f85d-be90-4334-b8d5-8021ec05283d
< 3.2.9
MEDIUM 6.1 The Poll Maker WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the mcount parameter found in the ~/… wordfence
2514c343-3a34-4580-abe8-fc0192408860 MEDIUM 6.1 The CloudFlare(R) Cache Purge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… wordfence
250d1bea-793d-4c13-976b-bfc3ff7d9160 MEDIUM 6.1 The Advanced Search by My Solr Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
24f2eafc-c8eb-4d78-af5e-1a589d7e4d21
< 5.3.2.1
MEDIUM 6.1 The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to … wordfence
24e8513c-f8d4-4e32-8212-191f5b5893b5
< 0.1.2
MEDIUM 6.1 The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before ou… wordfence
← Prev 972 973 974 975 976 977 978 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top