ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 993 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
19dc0b31-9e34-493c-ab38-6cae64c75162 MEDIUM 6.1 The WP Js External Link Info plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ and … wordfence
19d89e6c-72e7-48b1-bcc6-38d1f994cff6 MEDIUM 6.1 The Zalo Live Chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
19d394d8-bdc5-4cb5-b210-269197294020
< 2.2.76
MEDIUM 6.1 The Post Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2… wordfence
19cc7f5b-545a-4f68-bc37-269cc84364ad
< 9.1.8
MEDIUM 6.1 The NEX-Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 9.1… wordfence
19bd46d7-7ed9-4bef-9f8d-0e51ed59e533 MEDIUM 6.1 The AuMenu plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1.5 … wordfence
19b21013-136a-41b0-a667-39f23ccedf2e
< 1.7.1
MEDIUM 6.1 The Contact Form to DB plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.7.… wordfence
199d3a1f-bfde-4081-bb68-ebb6f9d360b2
< 4.4
MEDIUM 6.1 The tagDiv Composer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, but not includin… wordfence
19983f79-b439-4bb0-8f29-8312f1ff9791
< 1.10.0
MEDIUM 6.1 The gAppointments - Appointment booking addon for Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Si… wordfence
19796773-3d5f-458d-aab1-743b6835c71b
< 1.6.8
MEDIUM 6.1 The CMS Tree Page View plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_type' paramete… wordfence
19418da4-bef4-4cbc-901c-f2aeee39b3cf
< 4.11.5
MEDIUM 6.1 The Ajax Search Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
193eeb92-f0af-4c6a-ac44-3166023a3006
< 0.5.2
MEDIUM 6.1 The Formula theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in the 'ti_cu… wordfence
19388563-d0d0-4f15-966f-706b08bb8331 MEDIUM 6.1 The Contact Form 7 Round Robin Lead Distribution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
19342af0-9389-4fc3-8946-56d738a73d04 MEDIUM 6.1 The Download HTML TinyMCE Button plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… wordfence
192b8ab0-f80e-4c0e-9cc0-df567d5791a8
< 3.8.4
MEDIUM 6.1 The Target Video Easy Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
19286e18-f30d-40e8-80fa-cd1b4d065f80
< 4.9.5
MEDIUM 6.1 The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
19276873-0626-4ad7-a198-ed3312effbee
< 2.4.2
MEDIUM 6.1 The Stockholm Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
19257e49-addb-4882-af5f-8de0d90a4a86 MEDIUM 6.1 The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to Reflected Cross-Site Scri… wordfence
191fdd77-1119-4cd1-9de2-8a7e39a3385a
< 3.0.10
MEDIUM 6.1 The License Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up … wordfence
190f4aa9-3d99-494a-8ef4-e099dedbd9e4 MEDIUM 6.1 The Rizzi Guestbook plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
190a3b11-c6ca-4666-8c7f-b22bb4a4961d MEDIUM 6.1 The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… wordfence
19071f16-fa14-447c-ac71-73e1b4c783e1
< 3.14.34
MEDIUM 6.1 The 12 Step Meeting List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
1903354e-f53a-4005-b93b-c91d268f7a5d MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in pq_dialog.php in the Pro Quoter plugin 1.0 and earlier for WordPr… wordfence
190106bd-05ac-4a8f-b7a5-a042092a5713
< 1.7.4
MEDIUM 6.1 The WP Forum Server plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the (1) groupid parameter in a… wordfence
1900dbd2-9048-4da3-9aa1-fad89ba67a9e MEDIUM 6.1 The Gravel theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.6 due… wordfence
18fe9769-3681-4a5e-866a-640b4cc76199
< 4.3.9
MEDIUM 6.1 The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in a… wordfence
← Prev 990 991 992 993 994 995 996 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top