🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 997 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
156b9e3f-0a99-4fbc-88a4-1ed5e5e6b896
< 1.5.1.9
MEDIUM 6.1 The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress… wordfence
15672f90-3192-452c-a4f2-be6db00b7888 MEDIUM 6.1 The Custom Add User plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dmsg' parameter in ver… wordfence
15655362-b77f-4ba4-a823-17085de55f85 MEDIUM 6.1 The Simple Popup Newsletter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER[… wordfence
1564429b-0fb7-4c97-9802-8360e6ff3568 MEDIUM 6.1 The QR Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0… wordfence
15517a81-0913-4922-be2b-aaf9abc52a84
< 1.6.9
MEDIUM 6.1 XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galle… wordfence
154b3a1a-7246-42de-a555-2c655778d59e MEDIUM 6.1 The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
15416268-c040-46be-bf4d-252dc9a1ffad MEDIUM 6.1 The WP Profitshare plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
153a9a08-66b3-40fd-963d-93058c863a80
< 1.1.2
MEDIUM 6.1 wordfence
1535a174-ab59-4c6e-8080-ef818e00b070 MEDIUM 6.1 The Add User Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
15357b2b-acc4-45a2-9183-fd0e910ee943 MEDIUM 6.1 The Plestar Directory Listing plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… wordfence
153213ee-d1c6-4cc7-a297-e25266b705a8 MEDIUM 6.1 The Dyn Business Panel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… wordfence
15253d0c-3425-4065-94d2-969939e858ca
< 1.8.22
MEDIUM 6.1 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
1522d23b-7655-4fde-a18b-b46c6625185f
< 1.2.2.29
MEDIUM 6.1 The UsersWP – User Registration & User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi… wordfence
1507628c-4a81-47de-a06f-a5d573eebffb
< 1.1.0
MEDIUM 6.1 PayPal Pro Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). wordfence
14ffe10e-e1a6-4752-9ff9-d2b01a49521e
< 1.2.20
MEDIUM 6.1 The Email Subscription Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'queueemails' … wordfence
14fdd10e-283e-4978-9efa-73bc02c9c297 MEDIUM 6.1 The Posts Date Ranges plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
14fb6cde-3ab5-4360-add2-c0b0fa4ca114
< 2.1.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in Social Sharing Toolkit plugin before 2.1.2 for WordPress allows remote attac… wordfence
14f5a5c5-1c06-49fb-accd-0cbe992b9d3a MEDIUM 6.1 The Search order by product SKU for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in … wordfence
14f030bd-8d8d-4152-817d-d72c9b7a0152 MEDIUM 6.1 The VK Poster Group plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘vkp_repost’ parame… wordfence
14ee389b-8f98-4991-9a61-9da596013fea
< 0.2
MEDIUM 6.1 The Social Login by BestWebSoft plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includ… wordfence
14da4735-894e-408a-864b-cdc76feacde9
< 4.4.5
MEDIUM 6.1 The Video Conferencing with Zoom plugin for WordPress is vulnerable to Open Redirect in all versions up to, and includin… wordfence
14c3b53c-ba98-4e93-ba65-6da11816d7a6 MEDIUM 6.1 The MP-Ukagaka plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
14c24bff-91a1-402a-a9d1-a1a7800db62f MEDIUM 6.1 The Multi Item Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
14bf2f2e-4607-4817-ab8c-d986315964bc MEDIUM 6.1 The UberSlider PerpetuumMobile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
14aff362-2f49-460e-94db-1e0573c91c88 MEDIUM 6.1 The Google Font Fix plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
← Prev 994 995 996 997 998 999 1000 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top