🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 979 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
218f08d5-c1cb-462c-abc5-d5b41044f8aa
< 2.3.3
MEDIUM 6.1 The Activity Log plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions … wordfence
217cbfc8-1b5d-49b1-976e-237b4ed059d4 MEDIUM 6.1 The Kento Splash Screen plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
217c7916-0bd1-4499-8ecc-00961ddcc6e8 MEDIUM 6.1 The Mail plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3 due … wordfence
21614b80-f632-466b-9612-f616bbbc267d
< 2.4.1
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote a… wordfence
215ea2de-538b-4f24-98f8-67b8314453cd
< 3.4.7
MEDIUM 6.1 The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerabilit… wordfence
2156af57-d98b-4d0a-b7aa-0281c951c82f MEDIUM 6.1 Reflected XSS in wordpress plugin hdw-tube v1.2 via playlist parameter. wordfence
2153f7e2-0d39-4784-a1f5-aa77959306a7
< 4.0.3
MEDIUM 6.1 The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link. wordfence
2148809e-b7fe-4104-b70f-d4137c85e92f
< 1.3.12
MEDIUM 6.1 The eaSYNC plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3.11… wordfence
213a40fe-a143-46c9-b383-83c3fc31675d
< 3.2.2
MEDIUM 6.1 The Shopbuilder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3… wordfence
2134cdb7-6319-44b5-a280-781616caae04 MEDIUM 6.1 The Site Search 360 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
212e8f84-22a9-4b9e-b440-280f8569846f
< 1.6.73
MEDIUM 6.1 The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all… wordfence
21260efc-1518-4343-ad75-9992a97a58b1 MEDIUM 6.1 The Library Instruction Recorder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… wordfence
21241eb0-bfc7-4219-98de-a7a23d930c2d
< 2.8.0
MEDIUM 6.1 The Ad Inserter Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
210e9d94-ae2a-4dd9-a151-0bafbac68d18 MEDIUM 6.1 The Financial Stocks & Crypto Market Data Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi… wordfence
20e0367f-7f17-49fe-a19c-5defcea909e2 MEDIUM 6.1 The ContentOptin Lite – WP Content Upgrade Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
20b0c4c5-ee44-471a-bf6f-d2aa9fa2563d MEDIUM 6.1 The Google Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
20aa8703-ff25-4ac9-a7d8-2036e8c2574a MEDIUM 6.1 The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… wordfence
20a04283-4afd-442c-894c-98a765705404 MEDIUM 6.1 The Yahoo BOSS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
209e229f-2a96-4088-b84a-2ac1cd764081 MEDIUM 6.1 The Tijaji theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.43 du… wordfence
20842e95-4b91-4138-9e32-7c090724bf64
< 9.1.1
MEDIUM 6.1 The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in a… wordfence
20835df3-677c-4136-af50-46bc272e4f9e
< 3.7.2.4
MEDIUM 6.1 The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments plugin for WordPres… wordfence
207f7684-aeee-4267-ba29-ca9aacc0a690
< 5.1.7
MEDIUM 6.1 The Events Manager plugin before 5.1.7 for WordPress has XSS via JSON call links. wordfence
207b40fa-2062-48d6-990b-f05cbbf8fb8e MEDIUM 6.1 The Event Registration Calendar By vcita plugin, versions up to and including 3.10.0, and Online Payments – Get Paid w… wordfence
206cf03f-3536-4b13-8e8b-58032671c873 MEDIUM 6.1 The WOW Best CSS Compiler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
206a7117-0c4a-49e1-b7a4-74c330c6e4e2 MEDIUM 6.1 The Related Posts Line-up-Exactly by Milliard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve… wordfence
← Prev 976 977 978 979 980 981 982 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top