🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 985 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1b313177-d329-40a4-8a90-ce14b5cb90a9
< 1.2.9
MEDIUM 6.1 The Alpine PhotoTile For Instagram plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to 1.2.9 du… wordfence
1b1db6b8-f005-488f-b2cc-667acc700b0a
< 1.15.19
MEDIUM 6.1 The Form Maker by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a few parameters relate… wordfence
1b1d4180-091c-4679-a8d2-a6915ec05772
< 2.55
MEDIUM 6.1 The BestWebSoft's Twitter plugin before 2.55 for WordPress has XSS via several parameters. wordfence
1b1d2d03-f96a-4495-bdf9-0f48ad9cefd6 MEDIUM 6.1 The Admin Menu Organizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
1b1b61e6-2130-4462-a974-977dfe600371
< 3.3.102
MEDIUM 6.1 The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
1b000835-7f9d-44b4-92a3-ffce6e06d2ec
< 3.0.1
MEDIUM 6.1 The Feed Them Social plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘access_token’ par… wordfence
1aea4732-9e7d-406f-b848-ff223104f176
< 11.51
MEDIUM 6.1 The WPMobile.App plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
1ae01053-e6cd-4ddf-9e2a-4658cdb60f8e
< 1.29.2
MEDIUM 6.1 Multiple plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘path’ parameter included in … wordfence
1adcc627-c371-452b-95b7-25c659117116
< 16.0.8
MEDIUM 6.1 The SSO Login Premium Multisite plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 20… wordfence
1ad889f7-41cb-461f-8dc1-69236b06fb63
< 1.4
MEDIUM 6.1 The Add Any Extension to Pages plugin for WordPress is vulnerable to Cross-Site Scripting via the 'REQUEST_URI' value in… wordfence
1acfa5d1-c1ba-4ba5-9511-0f4adbe5b9ca
< 5.8
MEDIUM 6.1 The BP Profile Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
1aced2cc-13d6-47d1-8f27-4aa8448ae763
< 3.7.2
MEDIUM 6.1 The Support for CitiLights - Real Estate WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
1ac8fb0b-21a9-4b94-bb24-b349a7fe3305
< 5.6.0
MEDIUM 6.1 The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via … wordfence
1ab68c56-baf1-4507-86e8-9582a46eb544 MEDIUM 6.1 The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
1aadb04c-a483-4f9b-8246-3dd7e158fcc2
< 0.5.1
MEDIUM 6.1 The Ready! Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery and Cross-Site Scrip… wordfence
1a91e973-f669-49a6-8c74-f6fbc4dc8db9
< 1.12.6.4
MEDIUM 6.1 The Clean Login for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in version 1.1… wordfence
1a90be4a-1cc1-43b2-9990-a60c2837cacc MEDIUM 6.1 The Rebuild Permalinks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
1a7687fe-6246-4bd3-9d4f-e7fa6398f265 MEDIUM 6.1 The User Activation Email WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the uae-key parameter fou… wordfence
1a6fbb60-811a-4763-b301-694bc8d387e7
< 1.29.1
MEDIUM 6.1 The Forminator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
1a697391-f30d-403f-9046-8fa219a49302
< 2.4.1
MEDIUM 6.1 The GP Premium plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the message parameter in all ver… wordfence
1a67d846-d27c-4a82-a30d-813d9b37da1d
< 7.6.4
MEDIUM 6.1 The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
1a65e397-a4ec-414f-899c-cf381f475296 MEDIUM 6.1 The Visit Counter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
1a253ebd-c1c1-4a8f-a02a-67b244f840ce MEDIUM 6.1 The Google Map Locations plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
1a1af528-79c6-4197-b247-9789b290a642
< 11.2
MEDIUM 6.1 DOM based Cross-site scripting (XSS) vulnerability in the Bridge theme before 11.2 for WordPress allows remote attackers… wordfence
1a10af61-6451-4dda-aeda-ba8fa44bee35
< 2.2.7
MEDIUM 6.1 The SupportCandy – Helpdesk & Support Ticket System WordPress plugin before 2.2.7 does not have CSRF check in the wpsc… wordfence
← Prev 982 983 984 985 986 987 988 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top