πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 992 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
13e8f16b-b5a3-4be1-9557-e11cd9ffaea7
< 1.16
MEDIUM 6.1 The Enhanced Admin Plugin for WordPress is vulnerable to Cross-Site Scripting via the 'REQUEST_URI' variable in versions… wordfence
13e77d77-8f09-4fb9-8ff9-a8e66afe0393
< 2.1.6
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in services/diagnostics.php in the WordPress Social Login plugin 2.1.5 and earl… wordfence
13d53257-9dc7-4b7c-9472-72769099386c MEDIUM 6.1 The Custom Dashboard Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
13cfcc7a-8529-4bd5-9842-b9ad8eb5f4b3
< 1.8.22
MEDIUM 6.1 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
13cb5c62-34fb-4bbc-b42a-cc8a16d51258 MEDIUM 6.1 The Email Artillery (MASS EMAIL) plugin for WordPress is vulnerable to various Reflected Cross-Site Scripting via the 'c… wordfence
13ba9152-b9a0-4201-ba91-c41686b4d953
< 3.4.34
MEDIUM 6.1 In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable … wordfence
13a1e293-f539-4d19-8fe8-392c126fd1c4 MEDIUM 6.1 The intouch plugin for WordPress is vulnerable to Cross-Site Scripting via the 'intouch_failure' parameter in versions u… wordfence
1394b739-9d3a-4162-a7ca-3d20025eba52
< 1.4
MEDIUM 6.1 The GeoFlickr plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3… wordfence
1387338d-776d-47b3-882e-a395bc27bcb1 MEDIUM 6.1 The Ni WooCommerce Sales Report Email plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versio… wordfence
13843a16-7ae3-412d-a2ac-7a5ee556b6e2
< 20190907
MEDIUM 6.1 In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagg… wordfence
1383a701-d2b5-44fb-823f-0640ad4961fb MEDIUM 6.1 The iRobots.txt SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
13839b12-2823-4cc6-a950-f51f37391e60 MEDIUM 6.1 The Ultimate Push Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
1374efcf-028a-4707-bb28-3e4d49ed2877
< 5.4.4
MEDIUM 6.1 The Kleo theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 5.4.4 due to insufficient… wordfence
1371d1ea-a415-4cd8-bc99-a530670ffb94 MEDIUM 6.1 The All in One Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
136dabc7-7120-47ed-9b70-d2eae13819c0 MEDIUM 6.1 The Fare Calculator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
13657ad7-7185-4be2-98e2-aeaf8514ad4d
< 6.3.1
MEDIUM 6.1 The Salon booking system WordPress plugin before 6.3.1 does not properly sanitise and escape the First Name field when b… wordfence
135213d6-8058-4573-a97d-a95b0708d807
< 1.0.2
MEDIUM 6.1 wordfence
134b6e4d-c38f-4d52-b6dd-fd49ea0e6581
< 3.3.6.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress … wordfence
133c212e-9a9e-4538-a07d-05abac741ad9
< 3.1.0
MEDIUM 6.1 The Edwiser Bridge – WordPress Moodle LMS Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
133beb2d-0618-4ad7-922a-29df4d2bea1e
< 4.6.2
MEDIUM 6.1 The Beautiful Cookie Consent Banner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions… wordfence
132efd40-1c90-4d2a-a87c-504526b7a7d4 MEDIUM 6.1 The myLCO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter … wordfence
131fdc77-d7b8-4bbe-88b0-28d9aaa06a3b
< 1.1.0
MEDIUM 6.1 The Post Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0… wordfence
131b5d57-2af1-4cc5-8b4e-019a050c3bb8
< 1.0.83
MEDIUM 6.1 The Flixita theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜id’ parameter in all versio… wordfence
130ae053-2458-4789-a255-5df4753f1e8d MEDIUM 6.1 The odPhotogallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
1305abf3-542a-4f97-bbe9-1568d697aa82
< 3.6.4
MEDIUM 6.1 The WooTour plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.6.3… wordfence
← Prev 989 990 991 992 993 994 995 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top