🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 989 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
174c4050-8eed-4641-85d2-4b66702e03a6
< 4.8.73
MEDIUM 6.1 In the miniOrange SAML SP Single Sign On plugin before 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XS… wordfence
17422c79-494a-4c90-a48c-1aad9e0fa4c2
< 4.3.1
MEDIUM 6.1 The wp-database-backup plugin before 4.3.1 for WordPress has XSS. wordfence
172a8c2c-dbfe-425a-9091-c9f20290cf03 MEDIUM 6.1 The Simple Auto Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
1723a465-75ca-4fea-ad9c-d96ffb5625a8
< 3.1.29
MEDIUM 6.1 The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' … wordfence
171fe5db-0b43-47ba-b215-87ce9d7b5095 MEDIUM 6.1 The YANewsflash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
171faddd-c60c-4d07-834e-d8149703513b
< 1.4.7
MEDIUM 6.1 The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outp… wordfence
16e7a7c5-b845-4f28-bee6-fde54d003e13 MEDIUM 6.1 The WP SEO Tags WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the saq_txt_the_filter parameter in… wordfence
16e2c051-6ec6-4b09-8802-adb537fa9af0
< 2.8.3
MEDIUM 6.1 The Visual Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter i… wordfence
16d41531-5250-421e-93d6-29176e1f252d MEDIUM 6.1 The Import Users to MailChimp plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
16c9ed4a-9e9f-4f10-b3fd-7f0db2c86112
< 4.0.0
MEDIUM 6.1 The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets plugin for WordPress is vulnerable to Stored … wordfence
16bd14a1-e69b-4b7d-8c0e-a294e120d2a6
< 3.0.2
MEDIUM 6.1 The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page’… wordfence
16b8851c-171b-43cc-85ef-28c01d7e090f MEDIUM 6.1 The Blighty Explorer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
16b5ad20-a264-49fa-aafc-e137ac0d81fa MEDIUM 6.1 The WP Headmaster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
16a70662-d32c-4dfd-a1b2-0876ba4671ab MEDIUM 6.1 The Section Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
16a4ebde-7c92-4ad2-9c8d-3bef0a8c600b
< 1.2.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Welcart plugin before 1.2.2 for WordPress allows remote attackers to inj… wordfence
169f2767-da20-4199-9997-438a62f6aee4
< 1.28
MEDIUM 6.1 The reCaptcha by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’… wordfence
16919724-e495-492e-8cc7-639e6d8473c2
< 4.0.3
MEDIUM 6.1 The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the sr… wordfence
163f120e-533a-4054-b5d1-331950ad02a7 MEDIUM 6.1 The Windows Live Writer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
1638145c-2bc8-45d4-904e-b1aba124a0e3
< 1.4.1
MEDIUM 6.1 includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin … wordfence
162afd58-3534-401b-9119-c1c26e15cd0f
< 2.9.5
MEDIUM 6.1 The Welcart e-Commerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'upload_mode' parame… wordfence
15fbfb20-50c7-4390-afa3-e6b9c95a2551
< 3.1.7
MEDIUM 6.1 The Quick Interest Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
15f3ca33-50b8-4cd3-bcd1-5a73a3a06fc3
< 4.5.3.1
MEDIUM 6.1 The CKEditor plugin before 4.5.3.1 for WordPress has reflected XSS in the built-in (old) file browser. wordfence
15f2c277-45ba-40a8-8123-17e23afbf68b MEDIUM 6.1 The Tantyyellow theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
15f1a14e-7536-4f6e-ad6d-a3bcb09efec6
< 7.1.7
MEDIUM 6.1 The Nomupay Payment Processing Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … wordfence
15f00b65-8304-4132-a2cf-8145444ecfb1
< 4.4.3
MEDIUM 6.1 The NextScripts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘code’ parameter in ver… wordfence
← Prev 986 987 988 989 990 991 992 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top