🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 977 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
23518a21-7b76-4edb-9a35-b6f623ed50a7
< 3.4.7
MEDIUM 6.1 The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all version… wordfence
234df0e5-d1be-4354-8bfc-761bed1e9aa9
< 2.7.5
MEDIUM 6.1 The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in versions up to, and i… wordfence
234a847b-3ffa-4c5c-9bba-39df227de0bc
< 1.9.13
MEDIUM 6.1 The Tutor LMS plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 1.9.… wordfence
2345c972-9fd4-4709-8bde-315ab54f60e2
< 4.10.6
MEDIUM 6.1 The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… wordfence
233df260-be3f-4d4b-9af8-a31a3577df1a
< 2.2
MEDIUM 6.1 The Catch Duplicate Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
2339c392-49bc-4744-b82a-d40f3bb4a81e
< 1.1.10
MEDIUM 6.1 Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the valu… wordfence
23311ce1-0e94-4bff-8d92-388ccc600506
< 2.6.5
MEDIUM 6.1 The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues. wordfence
2326984b-8f2b-4922-8141-2fed0548101b MEDIUM 6.1 The wpSOL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.0. … wordfence
231dbf87-2e17-4b4b-9eac-34a8b4a791ba
< 2.0
MEDIUM 6.1 The Elements For Elementor plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions… wordfence
2314cfeb-52e4-40c5-91e9-ebd7d7eab809
< 4.8.2
MEDIUM 6.1 The Events Calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter. wordfence
23132298-f1de-4085-a76f-f007b8b7de15
< 7.13.12
MEDIUM 6.1 The WordPress Geolocation Plugin – CF Geo Plugin Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
22fd58a6-2bcb-4190-8440-a7df7848ad9e
< 2.6.2
MEDIUM 6.1 The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it … wordfence
22faab6d-a63f-4052-b7c6-92e11e4ca723
< 3.5.1
MEDIUM 6.1 The Securimage-WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘PHP_SELF’ parameter … wordfence
22fa10c0-4efd-4b4d-84a6-cc6db647f6dc
< 3.5.0
MEDIUM 6.1 The Team Members Showcase plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
22dcdd92-75d1-44aa-aaae-434ec4bdc20f
< 1.4.5
MEDIUM 6.1 The Auberge theme before 1.4.5 for WordPress has XSS via the genericons/example.html anchor identifier. wordfence
22dbd787-2b9a-4883-9203-c79fc241596d
< 1.0.3
MEDIUM 6.1 The WordPress Importer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
22d50526-e21f-412d-9eed-b9b1f48c3358
< 3.2.41
MEDIUM 6.1 The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ pa… wordfence
22cfbaa1-5412-4944-899c-7ae41d017384 MEDIUM 6.1 The Arya Multipurpose Pro theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter i… wordfence
22c03ddb-befe-4ac5-86b1-46d95d313b5e MEDIUM 6.1 The WPMovieLibrary plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
22bf5b65-8ec4-477c-a6bd-c90b99f560a8
< 1.5.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress a… wordfence
22b33944-443e-48fe-9fd0-4d48fe03072b MEDIUM 6.1 The New Year Firework plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'text' parameter in t… wordfence
22b16275-f46b-4338-b95f-1939ec85316d MEDIUM 6.1 The Coupon Tab for DirectoryPress (pp-coupon-tab) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v… wordfence
22ab3baa-34a3-4554-9c05-ebd5c9e5279b MEDIUM 6.1 The WP_DEBUG Toggle plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
22a9c0f6-7a20-4ed1-9afa-887adc790c80 MEDIUM 6.1 The pageMash > Page Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
22a0f10f-0a67-4f4a-99db-a625bec20bdc
< 1.7.1
MEDIUM 6.1 The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… wordfence
← Prev 974 975 976 977 978 979 980 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top