🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 996 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
16d41531-5250-421e-93d6-29176e1f252d MEDIUM 6.1 The Import Users to MailChimp plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
16c9ed4a-9e9f-4f10-b3fd-7f0db2c86112
< 4.0.0
MEDIUM 6.1 The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets plugin for WordPress is vulnerable to Stored … wordfence
16bd14a1-e69b-4b7d-8c0e-a294e120d2a6
< 3.0.2
MEDIUM 6.1 The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page’… wordfence
16b8851c-171b-43cc-85ef-28c01d7e090f MEDIUM 6.1 The Blighty Explorer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
16b5ad20-a264-49fa-aafc-e137ac0d81fa MEDIUM 6.1 The WP Headmaster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
16a70662-d32c-4dfd-a1b2-0876ba4671ab MEDIUM 6.1 The Section Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
16a4ebde-7c92-4ad2-9c8d-3bef0a8c600b
< 1.2.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Welcart plugin before 1.2.2 for WordPress allows remote attackers to inj… wordfence
169f2767-da20-4199-9997-438a62f6aee4
< 1.28
MEDIUM 6.1 The reCaptcha by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’… wordfence
16919724-e495-492e-8cc7-639e6d8473c2
< 4.0.3
MEDIUM 6.1 The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the sr… wordfence
163f120e-533a-4054-b5d1-331950ad02a7 MEDIUM 6.1 The Windows Live Writer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
1638145c-2bc8-45d4-904e-b1aba124a0e3
< 1.4.1
MEDIUM 6.1 includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin … wordfence
162afd58-3534-401b-9119-c1c26e15cd0f
< 2.9.5
MEDIUM 6.1 The Welcart e-Commerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'upload_mode' parame… wordfence
15fbfb20-50c7-4390-afa3-e6b9c95a2551
< 3.1.7
MEDIUM 6.1 The Quick Interest Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
15f3ca33-50b8-4cd3-bcd1-5a73a3a06fc3
< 4.5.3.1
MEDIUM 6.1 The CKEditor plugin before 4.5.3.1 for WordPress has reflected XSS in the built-in (old) file browser. wordfence
15f2c277-45ba-40a8-8123-17e23afbf68b MEDIUM 6.1 The Tantyyellow theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
15f1a14e-7536-4f6e-ad6d-a3bcb09efec6
< 7.1.7
MEDIUM 6.1 The Nomupay Payment Processing Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … wordfence
15f00b65-8304-4132-a2cf-8145444ecfb1
< 4.4.3
MEDIUM 6.1 The NextScripts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘code’ parameter in ver… wordfence
15e65a86-db8e-4a4a-b9c6-c688021a514f MEDIUM 6.1 The Testimonial Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF'… wordfence
15e06f6e-2a13-490e-8e41-d9f7db8e78e0 MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the wp-football plugin 1.1 and earlier for WordPress allow remote… wordfence
15d6cdb5-5259-46d5-8649-a3abcde4fb47 MEDIUM 6.1 The Unique UX plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.9… wordfence
15d66474-e215-4d28-b6fb-259c90053212
< 3.2
MEDIUM 6.1 The Portrait-Archiv.com Photostore plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pDeta… wordfence
15ce5666-f020-4264-989d-713e4520e012
< 0.9.69
MEDIUM 6.1 The Migration, Backup, Staging – WPvivid plugin before 0.9.69 does not have authorisation when adding remote storages,… wordfence
15b57809-6062-48ca-8572-26032928cd16
< 3.4.7
MEDIUM 6.1 The Survey Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in ve… wordfence
15967a0f-2512-4418-b503-b9d53032d40f
< 1.7.0
MEDIUM 6.1 The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter. wordfence
157b3095-b662-465e-a975-5b71b5d4ba2a
< 3.3.5
MEDIUM 6.1 wordfence
← Prev 993 994 995 996 997 998 999 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top