🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 983 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1d2ba8ea-a75f-4069-b67d-f832acb1deef
< 4.9.17
MEDIUM 6.1 The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' … wordfence
1d2aef81-f8f1-47a4-8c9c-e46e3a0cbe0d MEDIUM 6.1 The WooCommerce Order Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
1d2a3e10-e76b-4a5b-bb5a-2a99e48be094 MEDIUM 6.1 The TagGator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.54… wordfence
1d261e25-7355-4220-882c-f3266c64252a MEDIUM 6.1 The Awesome Weather Widget WordPress plugin through 3.0.2 does not sanitize the id parameter of its awesome_weather_refr… wordfence
1d24dbdf-8fb0-41c3-8c35-e0d65c6b96f5
< 3.3.9.3
MEDIUM 6.1 The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘question’ parameter in v… wordfence
1d18b3ad-57ea-40cb-8a35-0ae31efc8973 MEDIUM 6.1 The Flaming Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
1d0166c9-1349-45df-9e0f-ff4bc1a67c73
< 1.3.3
MEDIUM 6.1 The FormFacade – WordPress plugin for Google Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
1cf44639-60ce-4a3c-aa4a-550dd9327039
< 1.1.0
MEDIUM 6.1 wordfence
1ceae0dc-205a-4a24-a912-b632c9ca7e6f
< 10.6.7
MEDIUM 6.1 The Wp EMember plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER['REQUEST_URI'] in all v… wordfence
1cd9ebdc-8c97-47a5-9147-40684d74bddd MEDIUM 6.1 The Geotagged Media plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
1cbad810-530c-4160-af5d-7e57ecc40dac
< 4.1.5
MEDIUM 6.1 The Loops & Logic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
1c995da3-83c4-4734-8d4f-24c34f12919c
< 1.1.9
MEDIUM 6.1 The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?a… wordfence
1c6b2c4b-5ea5-471d-9114-d2b469b6c59b
< 2.3.7
MEDIUM 6.1 The CF7 Google Sheets Connector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘code’ … wordfence
1c5d214e-65e2-4158-a88f-58bef7c9952b MEDIUM 6.1 Reflected XSS in wordpress plugin hdw-tube v1.2 via channel parameter. wordfence
1c544990-9fd2-4f1b-a02c-a13959d68580 MEDIUM 6.1 The Buddypress Moderation plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
1c432dbe-8542-41de-966a-b2699d1685ce
< 3.0
MEDIUM 6.1 The Increase upload file size & Maximum Execution Time limit plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
1c3e1a05-ae8c-4438-afd9-d1d0a39484c2
< 3.18.14
MEDIUM 6.1 The WPPizza – A Restaurant Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions… wordfence
1c17909f-bf69-4d72-80d2-0574b964bb4f MEDIUM 6.1 The AWSA Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
1c120385-c761-4684-ab5c-f08cd803c253 MEDIUM 6.1 The Floating Window Music Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
1c0f9116-15b0-47e1-b842-aa76cc903ebf
< 2.0.0
MEDIUM 6.1 The Whizz Plugins plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
1c0e1973-0aa1-4787-b503-3b38476acdbb MEDIUM 6.1 The Elite Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
1c0a544a-b5f3-41bf-9313-28188662ea56 MEDIUM 6.1 The ResAds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions … wordfence
1c074e03-b452-4aea-aa1d-36657ba311e1
< 4.0.11
MEDIUM 6.1 The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page. wordfence
1c06a572-a0c0-477a-9f8f-abe355cb87f7 MEDIUM 6.1 The Make Email Customizer for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versio… wordfence
1bf8ebeb-71dc-468b-82a1-005e1c4e23d9 MEDIUM 6.1 The Login Watchdog plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
← Prev 980 981 982 983 984 985 986 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top