🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 987 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
191fdd77-1119-4cd1-9de2-8a7e39a3385a
< 3.0.10
MEDIUM 6.1 The License Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up … wordfence
190f4aa9-3d99-494a-8ef4-e099dedbd9e4 MEDIUM 6.1 The Rizzi Guestbook plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
190a3b11-c6ca-4666-8c7f-b22bb4a4961d MEDIUM 6.1 The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… wordfence
19071f16-fa14-447c-ac71-73e1b4c783e1
< 3.14.34
MEDIUM 6.1 The 12 Step Meeting List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
1903354e-f53a-4005-b93b-c91d268f7a5d MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in pq_dialog.php in the Pro Quoter plugin 1.0 and earlier for WordPr… wordfence
190106bd-05ac-4a8f-b7a5-a042092a5713
< 1.7.4
MEDIUM 6.1 The WP Forum Server plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the (1) groupid parameter in a… wordfence
1900dbd2-9048-4da3-9aa1-fad89ba67a9e MEDIUM 6.1 The Gravel theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.6 due… wordfence
18fe9769-3681-4a5e-866a-640b4cc76199
< 4.3.9
MEDIUM 6.1 The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in a… wordfence
18ea9880-817f-41d0-a552-b43deac46bb3 MEDIUM 6.1 The Hack me if you can plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
18e0140e-ac24-48c6-aea0-bb0da203a817
< 2.6.6
MEDIUM 6.1 The String locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sql-column' parameter i… wordfence
18ded977-5297-4b6f-b9f3-0567f995d08a
< 4.0.4.8
MEDIUM 6.1 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
18dacb4b-7eb7-4de2-b889-e36c11ad4a04
< 1.8
MEDIUM 6.1 wordfence
18d37650-057d-4cd1-bfeb-e40885d22566 MEDIUM 6.1 The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripti… wordfence
18d33d68-9719-4e74-a594-bc4add38ceee
< 2.1.1
MEDIUM 6.1 The Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '… wordfence
18c0f717-6825-4421-af53-68f1cf502f81
< 3.19.0
MEDIUM 6.1 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
18b54d30-b876-4704-9456-28df8db0efda MEDIUM 6.1 The GetSocial plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0… wordfence
18aa817d-80e0-4c6f-852f-c8a91c9507c4
< 1.5.3.4
MEDIUM 6.1 The Slideshow Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Gallerymessage’ … wordfence
189c2409-5111-489c-bd91-86f6a6a6cdcb MEDIUM 6.1 The Automotive Listings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
1899e5ec-ad87-4182-81b6-3b777d117e93
< 3.9.5
MEDIUM 6.1 The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg … wordfence
1889c1ba-f49f-474c-8d0a-0ae46fb92deb
< 2.7.7
MEDIUM 6.1 The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
1882bb92-8e4e-484f-bded-05802de9a64e
< 10.7.0
MEDIUM 6.1 The Wp EMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 10.7.0 (exclusive)… wordfence
187fa947-f041-4cfd-9b2a-ee4c9254f2b3
< 2.5.9
MEDIUM 6.1 The LTL Freight Quotes – Unishippers Edition plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in v… wordfence
1877f94c-3761-4af2-b093-cd2a4e60d63b MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Conversion Ninja plugin for WordPress allows remote attackers to inject … wordfence
18696937-5cc5-4e14-940d-fc25468377a3 MEDIUM 6.1 The Lesson Plan Book plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']`… wordfence
1862242a-9a00-4e6b-94a2-5599200f1040 MEDIUM 6.1 The WP MultiTasking – WP Utilities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all version… wordfence
← Prev 984 985 986 987 988 989 990 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top