πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 976 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
24e6f868-258b-4b32-8215-bb2f360cda06
< 1.8.3
MEDIUM 6.1 The WP Event Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
24e27ec0-a543-4900-839e-fbe4bc5a746f MEDIUM 6.1 The Debt Calculator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
24d63989-e0b7-46fd-98db-c2c17c90a270 MEDIUM 6.1 The Flexo Counter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
24d050ad-0816-46a3-a37e-17356acf88d2 MEDIUM 6.1 Multiple cross-site request forgery (CSRF) vulnerabilities in the yURL ReTwitt plugin 1.4 and earlier for WordPress allo… wordfence
24c7e7da-39b4-4969-b24f-be7a8628236b
< 6.2.7
MEDIUM 6.1 The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX … wordfence
24c67243-0452-4820-bfb4-b7ac4804aa4b
< 11.6.1
MEDIUM 6.1 The The7 theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the legacy "DT Flickr" widget in versio… wordfence
24c3d004-da8b-40ec-b52e-6923d4c824e8 MEDIUM 6.1 The Daily Edition theme for WordPress is vulnerable to Cross-Site Scripting via the 'id' parameter in versions up to, an… wordfence
24b7e8d7-a9f2-4192-97c0-b7cbc1669a2a
< 3.6.8
MEDIUM 6.1 The WP Timeline – Vertical and Horizontal timeline plugin plugin for WordPress is vulnerable to Reflected Cross-Site S… wordfence
24ac60fe-d751-43c7-89c1-5c0c9651e8f8
< 2024
MEDIUM 6.1 The Socialdriver plugin for WordPress is vulnerable to prototype pollution in all versions up to 2024 (exclusive) due to… wordfence
24a6b716-2f23-447c-b156-6124538efbcd MEDIUM 6.1 The Custom Widget Creator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
2490a51c-718f-463b-ab80-82d48deb2f1a
< 1.43
MEDIUM 6.1 The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to… wordfence
24798f70-07bd-435c-ac92-97a6842b78c7 MEDIUM 6.1 The Countdown Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
24759d97-2b00-4812-8407-640b545a235a
< 1.3.2.3
MEDIUM 6.1 The WordPress to Freshsales Integration plugin for WordPress is vulnerable to Cross-Site Scripting via several parameter… wordfence
24349a73-d543-433b-9f7c-b12f914fc80f MEDIUM 6.1 The Forym plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜s’ parameter in versions up… wordfence
23c9cb06-70c0-4d91-8147-256a77c65d7a
< 1.6.3
MEDIUM 6.1 The About Author plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
23c7a244-4dee-403d-aaad-f6ca97567d1c MEDIUM 6.1 The Dashboard Notepads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
23b56bc5-0253-43bf-a4db-f924bfaf1225 MEDIUM 6.1 The Gearside Developer Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… wordfence
23a3a4c5-0af0-4b5f-b3c7-bf670efea84f
< 6.3
MEDIUM 6.1 The Analytics Insights – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Open Redirect … wordfence
239bdac1-c14b-42ff-bee5-130d0bf3394c
< 2.1.0.2
MEDIUM 6.1 The Custom Sidebars plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the cs-msg parameter in ver… wordfence
238dc80f-0d82-44e2-a950-321defb2361b MEDIUM 6.1 The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundat… wordfence
2375027c-9619-40fc-811d-7f4ba02bee53 MEDIUM 6.1 The aBitGone CommentSafe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
236dd639-7f05-4fe8-bb81-5d023ebe7962
< 1.1
MEDIUM 6.1 An issue was discovered in the MULTIDOTS Advance Search for WooCommerce plugin 1.0.9 and earlier for WordPress. This plu… wordfence
2369c5f6-ba25-4bd9-a2b2-508399f285f1 MEDIUM 6.1 The Driving Directions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
2363b412-f14b-41e5-a1a7-707f5db2ce65
< 1.2
MEDIUM 6.1 The Bulk Page Stub Creator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
23610b0a-3a70-4f67-9ff3-6291e2912922 MEDIUM 6.1 The Aardvark theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.6.3… wordfence
← Prev 973 974 975 976 977 978 979 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top