🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 988 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1861d943-ac58-4a44-ab50-e39101e82013
< 3.12.1
MEDIUM 6.1 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
185f9dc4-39e6-422a-97e2-7e8814ccf64a
< 3.0.4
MEDIUM 6.1 The Real Estate 7 theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ct_keyword’ parameter… wordfence
183d1be9-4c05-4107-b039-3711034ef774 MEDIUM 6.1 The WP Media Optimizer (.webp) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wpmowebp-… wordfence
181be35c-0aec-48b0-a43b-181284cdb2e2
< 1.2.1
MEDIUM 6.1 The event-notifier plugin before 1.2.1 for WordPress has XSS via the loading animation. wordfence
17ffdd6d-3c6c-4f47-9f1c-a0f4c0f5fcdf
< 2.6
MEDIUM 6.1 The Restrict User Access – Membership Plugin with Force plugin for WordPress is vulnerable to Reflected Cross-Site Scr… wordfence
17fa37ae-5683-4b5f-995f-934f469141a5
< 3.0.8
MEDIUM 6.1 The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
17dcb057-6fa6-488c-9d59-22dcdba3fd2f
< 3.74
MEDIUM 6.1 The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting. wordfence
17d3a2e4-d6f3-4302-91b0-2408ccd8958a
< 6.0.27
MEDIUM 6.1 The WP Google Maps plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 6.0.26 v… wordfence
17d11c96-fd3c-478e-9b0e-ba58116ee27f
< 1.16.66
MEDIUM 6.1 The UpdraftPlus WordPress Backup Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ba… wordfence
17cffc76-7b41-4dc0-90cc-695b6f5474ce
< 1.0.3
MEDIUM 6.1 The Clio Grow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0… wordfence
17cb7420-b4e1-4959-beae-d3c0a8c4b1ff
< 2.3.2
MEDIUM 6.1 The VR Calendar for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'vrc_msg' and 'vrc_msg_type' param… wordfence
17cb080f-83f5-4917-af76-bfcc741ae053
< 5.12.8
MEDIUM 6.1 The Coupon Affiliates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
17bcf47f-4fca-4e16-a097-ed8e0f3420d0 MEDIUM 6.1 The .TUBE Video Curator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
17b8da07-1cfd-46d3-92fd-5d2d70c8c470 MEDIUM 6.1 The .htaccess Login block plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
17ae3f22-6426-48f7-93e6-c0ad515b329a
< 3.4.3
MEDIUM 6.1 The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due … wordfence
17acbf24-b0ae-42c8-af8f-17e82213507d MEDIUM 6.1 The WP – Bulk SMS – by SMS.to plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' pa… wordfence
177900d6-c52e-4ac4-a74d-412e453f9d05 MEDIUM 6.1 The Pagerank Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in a… wordfence
1775a56e-3590-499e-89b6-79d69d80fa0e
< 3.4.4
MEDIUM 6.1 The qtranslate-x plugin before 3.4.4 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page… wordfence
176b9fe6-e025-45c4-83ac-4a782c25e041
< 2.0.9
MEDIUM 6.1 The Phox Hosting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
1767776f-b130-4123-8a84-ce4a21248cff
< 7.4.3
MEDIUM 6.1 The Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin for WordPress is vulnerable to Stored Cross… wordfence
175d1830-2ece-40f6-b862-cb853dae96f5
< 2.6.8
MEDIUM 6.1 The WooCommerce Fattureincloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
175cf134-ece5-4c31-80e5-f3ac62fc20bd
< 2.2
MEDIUM 6.1 The hmd theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.0 du… wordfence
175b64d3-0abd-4a65-b419-d6248a7deb2f
< 3.4.8
MEDIUM 6.1 The Elementor Website Builder plugin for WordPress is vulnerable to DOM-based Cross-Site Scripting via the '#elementor-a… wordfence
175a69da-c47a-40f3-98c7-7cfcdf98f9f6
< 7.0.6
MEDIUM 6.1 The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to Reflected Cross… wordfence
1754cced-d3e4-40af-b0e9-9089a92db3dc MEDIUM 6.1 The Base64 Encoder/Decoder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'string' paramet… wordfence
← Prev 985 986 987 988 989 990 991 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top