🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 994 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
18ea9880-817f-41d0-a552-b43deac46bb3 MEDIUM 6.1 The Hack me if you can plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
18e0140e-ac24-48c6-aea0-bb0da203a817
< 2.6.6
MEDIUM 6.1 The String locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sql-column' parameter i… wordfence
18ded977-5297-4b6f-b9f3-0567f995d08a
< 4.0.4.8
MEDIUM 6.1 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
18dacb4b-7eb7-4de2-b889-e36c11ad4a04
< 1.8
MEDIUM 6.1 wordfence
18d37650-057d-4cd1-bfeb-e40885d22566 MEDIUM 6.1 The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripti… wordfence
18d33d68-9719-4e74-a594-bc4add38ceee
< 2.1.1
MEDIUM 6.1 The Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '… wordfence
18c0f717-6825-4421-af53-68f1cf502f81
< 3.19.0
MEDIUM 6.1 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
18b54d30-b876-4704-9456-28df8db0efda MEDIUM 6.1 The GetSocial plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0… wordfence
18aa817d-80e0-4c6f-852f-c8a91c9507c4
< 1.5.3.4
MEDIUM 6.1 The Slideshow Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Gallerymessage’ … wordfence
189c2409-5111-489c-bd91-86f6a6a6cdcb MEDIUM 6.1 The Automotive Listings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
1899e5ec-ad87-4182-81b6-3b777d117e93
< 3.9.5
MEDIUM 6.1 The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg … wordfence
1889c1ba-f49f-474c-8d0a-0ae46fb92deb
< 2.7.7
MEDIUM 6.1 The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
1882bb92-8e4e-484f-bded-05802de9a64e
< 10.7.0
MEDIUM 6.1 The Wp EMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 10.7.0 (exclusive)… wordfence
187fa947-f041-4cfd-9b2a-ee4c9254f2b3
< 2.5.9
MEDIUM 6.1 The LTL Freight Quotes – Unishippers Edition plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in v… wordfence
1877f94c-3761-4af2-b093-cd2a4e60d63b MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Conversion Ninja plugin for WordPress allows remote attackers to inject … wordfence
18696937-5cc5-4e14-940d-fc25468377a3 MEDIUM 6.1 The Lesson Plan Book plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']`… wordfence
1862242a-9a00-4e6b-94a2-5599200f1040 MEDIUM 6.1 The WP MultiTasking – WP Utilities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all version… wordfence
1861d943-ac58-4a44-ab50-e39101e82013
< 3.12.1
MEDIUM 6.1 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
185f9dc4-39e6-422a-97e2-7e8814ccf64a
< 3.0.4
MEDIUM 6.1 The Real Estate 7 theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ct_keyword’ parameter… wordfence
183d1be9-4c05-4107-b039-3711034ef774 MEDIUM 6.1 The WP Media Optimizer (.webp) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wpmowebp-… wordfence
181be35c-0aec-48b0-a43b-181284cdb2e2
< 1.2.1
MEDIUM 6.1 The event-notifier plugin before 1.2.1 for WordPress has XSS via the loading animation. wordfence
17ffdd6d-3c6c-4f47-9f1c-a0f4c0f5fcdf
< 2.6
MEDIUM 6.1 The Restrict User Access – Membership Plugin with Force plugin for WordPress is vulnerable to Reflected Cross-Site Scr… wordfence
17fa37ae-5683-4b5f-995f-934f469141a5
< 3.0.8
MEDIUM 6.1 The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
17dcb057-6fa6-488c-9d59-22dcdba3fd2f
< 3.74
MEDIUM 6.1 The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting. wordfence
17d3a2e4-d6f3-4302-91b0-2408ccd8958a
< 6.0.27
MEDIUM 6.1 The WP Google Maps plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 6.0.26 v… wordfence
← Prev 991 992 993 994 995 996 997 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top