🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 986 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1a020b1a-f0de-45c6-9750-be5154042949 MEDIUM 6.1 The TheBi theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.5 du… wordfence
19fbb332-f660-4572-82a3-c68e0bc7efcf
< 2.5.4
MEDIUM 6.1 The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Cross-Site Scripting via the 'lp_s_l… wordfence
19f97cc8-4a35-44fd-b9f5-978f5997d08a
< 1.1.8
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appoint… wordfence
19f8eb9b-f416-4ef4-bb75-f561579ce22f
< 1.3
MEDIUM 6.1 The Ultimate Classified Listings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… wordfence
19ef4080-0463-4a5c-a532-4877f60c82dc MEDIUM 6.1 The Featured Posts Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
19e8d0a3-56b1-4d4a-ad49-f28707d3b037
< 2.2
MEDIUM 6.1 The Subscription DNA® plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
19e7a841-e7b0-410d-ae33-f31811efd919
< 2.21.2
MEDIUM 6.1 The ArtPlacer Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
19e1421d-8cb4-44b6-a982-769539b19582 MEDIUM 6.1 The Stumble! for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S… wordfence
19dc0b31-9e34-493c-ab38-6cae64c75162 MEDIUM 6.1 The WP Js External Link Info plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ and … wordfence
19d89e6c-72e7-48b1-bcc6-38d1f994cff6 MEDIUM 6.1 The Zalo Live Chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
19d394d8-bdc5-4cb5-b210-269197294020
< 2.2.76
MEDIUM 6.1 The Post Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2… wordfence
19cc7f5b-545a-4f68-bc37-269cc84364ad
< 9.1.8
MEDIUM 6.1 The NEX-Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 9.1… wordfence
19bd46d7-7ed9-4bef-9f8d-0e51ed59e533 MEDIUM 6.1 The AuMenu plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1.5 … wordfence
19b21013-136a-41b0-a667-39f23ccedf2e
< 1.7.1
MEDIUM 6.1 The Contact Form to DB plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.7.… wordfence
199d3a1f-bfde-4081-bb68-ebb6f9d360b2
< 4.4
MEDIUM 6.1 The tagDiv Composer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, but not includin… wordfence
19983f79-b439-4bb0-8f29-8312f1ff9791
< 1.10.0
MEDIUM 6.1 The gAppointments - Appointment booking addon for Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Si… wordfence
19796773-3d5f-458d-aab1-743b6835c71b
< 1.6.8
MEDIUM 6.1 The CMS Tree Page View plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_type' paramete… wordfence
19418da4-bef4-4cbc-901c-f2aeee39b3cf
< 4.11.5
MEDIUM 6.1 The Ajax Search Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
193eeb92-f0af-4c6a-ac44-3166023a3006
< 0.5.2
MEDIUM 6.1 The Formula theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in the 'ti_cu… wordfence
19388563-d0d0-4f15-966f-706b08bb8331 MEDIUM 6.1 The Contact Form 7 Round Robin Lead Distribution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
19342af0-9389-4fc3-8946-56d738a73d04 MEDIUM 6.1 The Download HTML TinyMCE Button plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… wordfence
192b8ab0-f80e-4c0e-9cc0-df567d5791a8
< 3.8.4
MEDIUM 6.1 The Target Video Easy Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
19286e18-f30d-40e8-80fa-cd1b4d065f80
< 4.9.5
MEDIUM 6.1 The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
19276873-0626-4ad7-a198-ed3312effbee
< 2.4.2
MEDIUM 6.1 The Stockholm Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
19257e49-addb-4882-af5f-8de0d90a4a86 MEDIUM 6.1 The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to Reflected Cross-Site Scri… wordfence
← Prev 983 984 985 986 987 988 989 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top