🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 990 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
15e65a86-db8e-4a4a-b9c6-c688021a514f MEDIUM 6.1 The Testimonial Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF'… wordfence
15e06f6e-2a13-490e-8e41-d9f7db8e78e0 MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the wp-football plugin 1.1 and earlier for WordPress allow remote… wordfence
15d6cdb5-5259-46d5-8649-a3abcde4fb47 MEDIUM 6.1 The Unique UX plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.9… wordfence
15d66474-e215-4d28-b6fb-259c90053212
< 3.2
MEDIUM 6.1 The Portrait-Archiv.com Photostore plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pDeta… wordfence
15ce5666-f020-4264-989d-713e4520e012
< 0.9.69
MEDIUM 6.1 The Migration, Backup, Staging – WPvivid plugin before 0.9.69 does not have authorisation when adding remote storages,… wordfence
15b57809-6062-48ca-8572-26032928cd16
< 3.4.7
MEDIUM 6.1 The Survey Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in ve… wordfence
15967a0f-2512-4418-b503-b9d53032d40f
< 1.7.0
MEDIUM 6.1 The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter. wordfence
157b3095-b662-465e-a975-5b71b5d4ba2a
< 3.3.5
MEDIUM 6.1 wordfence
156b9e3f-0a99-4fbc-88a4-1ed5e5e6b896
< 1.5.1.9
MEDIUM 6.1 The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress… wordfence
15672f90-3192-452c-a4f2-be6db00b7888 MEDIUM 6.1 The Custom Add User plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dmsg' parameter in ver… wordfence
15655362-b77f-4ba4-a823-17085de55f85 MEDIUM 6.1 The Simple Popup Newsletter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER[… wordfence
1564429b-0fb7-4c97-9802-8360e6ff3568 MEDIUM 6.1 The QR Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0… wordfence
15517a81-0913-4922-be2b-aaf9abc52a84
< 1.6.9
MEDIUM 6.1 XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galle… wordfence
154b3a1a-7246-42de-a555-2c655778d59e MEDIUM 6.1 The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
15416268-c040-46be-bf4d-252dc9a1ffad MEDIUM 6.1 The WP Profitshare plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
153a9a08-66b3-40fd-963d-93058c863a80
< 1.1.2
MEDIUM 6.1 wordfence
1535a174-ab59-4c6e-8080-ef818e00b070 MEDIUM 6.1 The Add User Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
15357b2b-acc4-45a2-9183-fd0e910ee943 MEDIUM 6.1 The Plestar Directory Listing plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… wordfence
153213ee-d1c6-4cc7-a297-e25266b705a8 MEDIUM 6.1 The Dyn Business Panel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… wordfence
15253d0c-3425-4065-94d2-969939e858ca
< 1.8.22
MEDIUM 6.1 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
1522d23b-7655-4fde-a18b-b46c6625185f
< 1.2.2.29
MEDIUM 6.1 The UsersWP – User Registration & User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi… wordfence
1507628c-4a81-47de-a06f-a5d573eebffb
< 1.1.0
MEDIUM 6.1 PayPal Pro Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). wordfence
14ffe10e-e1a6-4752-9ff9-d2b01a49521e
< 1.2.20
MEDIUM 6.1 The Email Subscription Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'queueemails' … wordfence
14fdd10e-283e-4978-9efa-73bc02c9c297 MEDIUM 6.1 The Posts Date Ranges plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
14fb6cde-3ab5-4360-add2-c0b0fa4ca114
< 2.1.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in Social Sharing Toolkit plugin before 2.1.2 for WordPress allows remote attac… wordfence
← Prev 987 988 989 990 991 992 993 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top