🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 995 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
17d11c96-fd3c-478e-9b0e-ba58116ee27f
< 1.16.66
MEDIUM 6.1 The UpdraftPlus WordPress Backup Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ba… wordfence
17cffc76-7b41-4dc0-90cc-695b6f5474ce
< 1.0.3
MEDIUM 6.1 The Clio Grow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0… wordfence
17cb7420-b4e1-4959-beae-d3c0a8c4b1ff
< 2.3.2
MEDIUM 6.1 The VR Calendar for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'vrc_msg' and 'vrc_msg_type' param… wordfence
17cb080f-83f5-4917-af76-bfcc741ae053
< 5.12.8
MEDIUM 6.1 The Coupon Affiliates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
17bcf47f-4fca-4e16-a097-ed8e0f3420d0 MEDIUM 6.1 The .TUBE Video Curator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
17b8da07-1cfd-46d3-92fd-5d2d70c8c470 MEDIUM 6.1 The .htaccess Login block plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
17ae3f22-6426-48f7-93e6-c0ad515b329a
< 3.4.3
MEDIUM 6.1 The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due … wordfence
17acbf24-b0ae-42c8-af8f-17e82213507d MEDIUM 6.1 The WP – Bulk SMS – by SMS.to plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' pa… wordfence
177900d6-c52e-4ac4-a74d-412e453f9d05 MEDIUM 6.1 The Pagerank Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in a… wordfence
1775a56e-3590-499e-89b6-79d69d80fa0e
< 3.4.4
MEDIUM 6.1 The qtranslate-x plugin before 3.4.4 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page… wordfence
176b9fe6-e025-45c4-83ac-4a782c25e041
< 2.0.9
MEDIUM 6.1 The Phox Hosting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
1767776f-b130-4123-8a84-ce4a21248cff
< 7.4.3
MEDIUM 6.1 The Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin for WordPress is vulnerable to Stored Cross… wordfence
175d1830-2ece-40f6-b862-cb853dae96f5
< 2.6.8
MEDIUM 6.1 The WooCommerce Fattureincloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
175cf134-ece5-4c31-80e5-f3ac62fc20bd
< 2.2
MEDIUM 6.1 The hmd theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.0 du… wordfence
175b64d3-0abd-4a65-b419-d6248a7deb2f
< 3.4.8
MEDIUM 6.1 The Elementor Website Builder plugin for WordPress is vulnerable to DOM-based Cross-Site Scripting via the '#elementor-a… wordfence
175a69da-c47a-40f3-98c7-7cfcdf98f9f6
< 7.0.6
MEDIUM 6.1 The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to Reflected Cross… wordfence
1754cced-d3e4-40af-b0e9-9089a92db3dc MEDIUM 6.1 The Base64 Encoder/Decoder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'string' paramet… wordfence
174c4050-8eed-4641-85d2-4b66702e03a6
< 4.8.73
MEDIUM 6.1 In the miniOrange SAML SP Single Sign On plugin before 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XS… wordfence
17422c79-494a-4c90-a48c-1aad9e0fa4c2
< 4.3.1
MEDIUM 6.1 The wp-database-backup plugin before 4.3.1 for WordPress has XSS. wordfence
172a8c2c-dbfe-425a-9091-c9f20290cf03 MEDIUM 6.1 The Simple Auto Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
1723a465-75ca-4fea-ad9c-d96ffb5625a8
< 3.1.29
MEDIUM 6.1 The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' … wordfence
171fe5db-0b43-47ba-b215-87ce9d7b5095 MEDIUM 6.1 The YANewsflash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
171faddd-c60c-4d07-834e-d8149703513b
< 1.4.7
MEDIUM 6.1 The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outp… wordfence
16e7a7c5-b845-4f28-bee6-fde54d003e13 MEDIUM 6.1 The WP SEO Tags WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the saq_txt_the_filter parameter in… wordfence
16e2c051-6ec6-4b09-8802-adb537fa9af0
< 2.8.3
MEDIUM 6.1 The Visual Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter i… wordfence
← Prev 992 993 994 995 996 997 998 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top