ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 978 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
228de538-90c7-4f7d-a076-dd0a01458e38 MEDIUM 6.1 The Add Shortcodes Actions And Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … wordfence
22754d5f-a048-4734-ae11-30a26d6608ce MEDIUM 6.1 The Visitor Stats Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
22716408-8015-4ada-965b-4941a4b0e38c MEDIUM 6.1 The BVD Easy Gallery Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
226dba48-e984-4149-bc0e-aacedb35bcdf MEDIUM 6.1 The Altima Lookbook Free for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all ver… wordfence
22602d63-235a-4bdb-b907-e61be04e96c5
< 1.8
MEDIUM 6.1 The WP Easy Gallery plugin for WordPress is vulnerable to Cross-Site Scripting via the 'select_gallery' and 'galleryId' … wordfence
225ac126-7448-4faf-92c7-ee96831b272e
< 3.17.2
MEDIUM 6.1 The WPPizza plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple GET parameters in versions… wordfence
2250d512-dfe0-47d3-a61f-4e501d105f30
< 3.1.4
MEDIUM 6.1 The Adifier (Premium Theme) theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter… wordfence
224bf516-fac7-492f-87b9-912472ca01c9
< 1.32
MEDIUM 6.1 The WP Armour Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
22479c6a-83ea-4c09-b192-4384ffbdcbf7
< 3.0.0
MEDIUM 6.1 The EventPrime plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.… wordfence
223ace0a-5a98-4714-90d5-06fe96bc9a2d MEDIUM 6.1 Multiple cross-site request forgery (CSRF) vulnerabilities in the SimpleFlickr plugin 3.0.3 and earlier for WordPress al… wordfence
222325e9-3048-45f7-9a66-a713d096d44e
< 3.9.3
MEDIUM 6.1 The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id par… wordfence
221a8ff6-1f6e-41a0-82ef-eaa14ff84a26
< 1.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in index.php in the WordPress Responsive Preview plugin before 1.2 for WordPres… wordfence
2211d0d0-e7ab-485f-81b0-f52f87b7d01e
< 1.6.6
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the WP Favorite Posts plugin before 1.6.6 for WordPress allows remote attack… wordfence
220bafb6-2d34-4ee2-88a2-3913911bbea6 MEDIUM 6.1 The Awesome Shortcodes For Genesis plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.1.8. Th… wordfence
22074d7a-5dbd-4a0c-bc5d-e4c983e5edb4
< 20240502
MEDIUM 6.1 wordfence
2204017a-0363-4f2f-909a-e0826463477c
< 3.7.6
MEDIUM 6.1 The Church Admin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $what variable parameter i… wordfence
22025f2d-763a-4dbf-bad9-b71934195f78
< 4.1.4
MEDIUM 6.1 The Houzez theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.1… wordfence
220133fe-ebf3-4cfe-8882-1c961b384ff3
< 8.0.08
MEDIUM 6.1 There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka … wordfence
22005d74-de46-4b0b-baaf-0bfd69d01240
< 2.4.9
MEDIUM 6.1 The Credova_Financial plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
21fe167a-9925-438d-974d-66bbe676ed29 MEDIUM 6.1 The Flags Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
21fb5a51-f1e6-49d2-8289-4f4146bc9b28
< 2.5.0
MEDIUM 6.1 The twitter-cards-meta plugin before 2.5.0 for WordPress has XSS via several parameters. wordfence
21dd2899-cb2d-4266-be79-bdf00e60e9a7
< 11.0
MEDIUM 6.1 An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.… wordfence
21d8a074-f38b-4799-a7c2-92a5e7142924 MEDIUM 6.1 The Libro de Reclamaciones y Quejas plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
21a15a21-1d35-4fbc-9c01-ded68287fc65
< 2.5.6
MEDIUM 6.1 The Reality theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.5.5 … wordfence
2196197f-ccae-4893-b939-12980d20b9f6 MEDIUM 6.1 The Bit.ly linker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
← Prev 975 976 977 978 979 980 981 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top