πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 999 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1387338d-776d-47b3-882e-a395bc27bcb1 MEDIUM 6.1 The Ni WooCommerce Sales Report Email plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versio… wordfence
13843a16-7ae3-412d-a2ac-7a5ee556b6e2
< 20190907
MEDIUM 6.1 In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagg… wordfence
1383a701-d2b5-44fb-823f-0640ad4961fb MEDIUM 6.1 The iRobots.txt SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
13839b12-2823-4cc6-a950-f51f37391e60 MEDIUM 6.1 The Ultimate Push Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
1374efcf-028a-4707-bb28-3e4d49ed2877
< 5.4.4
MEDIUM 6.1 The Kleo theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 5.4.4 due to insufficient… wordfence
1371d1ea-a415-4cd8-bc99-a530670ffb94 MEDIUM 6.1 The All in One Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
136dabc7-7120-47ed-9b70-d2eae13819c0 MEDIUM 6.1 The Fare Calculator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
13657ad7-7185-4be2-98e2-aeaf8514ad4d
< 6.3.1
MEDIUM 6.1 The Salon booking system WordPress plugin before 6.3.1 does not properly sanitise and escape the First Name field when b… wordfence
135213d6-8058-4573-a97d-a95b0708d807
< 1.0.2
MEDIUM 6.1 wordfence
134b6e4d-c38f-4d52-b6dd-fd49ea0e6581
< 3.3.6.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress … wordfence
133c212e-9a9e-4538-a07d-05abac741ad9
< 3.1.0
MEDIUM 6.1 The Edwiser Bridge – WordPress Moodle LMS Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
133beb2d-0618-4ad7-922a-29df4d2bea1e
< 4.6.2
MEDIUM 6.1 The Beautiful Cookie Consent Banner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions… wordfence
132efd40-1c90-4d2a-a87c-504526b7a7d4 MEDIUM 6.1 The myLCO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter … wordfence
131fdc77-d7b8-4bbe-88b0-28d9aaa06a3b
< 1.1.0
MEDIUM 6.1 The Post Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0… wordfence
131b5d57-2af1-4cc5-8b4e-019a050c3bb8
< 1.0.83
MEDIUM 6.1 The Flixita theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜id’ parameter in all versio… wordfence
130ae053-2458-4789-a255-5df4753f1e8d MEDIUM 6.1 The odPhotogallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
1305abf3-542a-4f97-bbe9-1568d697aa82
< 3.6.4
MEDIUM 6.1 The WooTour plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.6.3… wordfence
12e74e1a-71d0-4447-ac77-62073af5de88
< 2.8.1
MEDIUM 6.1 The kingcomposer plugin up to 2.8 for WordPress has wp-admin/admin.php?page=kc-mapper id XSS. wordfence
12946a87-0b61-45ea-aae3-385d860b0db8
< 1.1.1
MEDIUM 6.1 The Easy Digital Downloads (EDD) Twenty-Twelve theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.… wordfence
128cad05-4dda-47fe-bbb4-471371613728 MEDIUM 6.1 The Narnoo Operator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
125a1d8d-8cd9-439c-b765-198ad369f987
< 1.5
MEDIUM 6.1 The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! plu… wordfence
125517dd-7caf-4774-9e21-e8648b633657 MEDIUM 6.1 The Increase Sociability plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
125354d8-95b5-4498-be66-8673b6d9aaff MEDIUM 6.1 The My Favorite Car plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
12447571-7770-4872-afb3-eaf11d5b47cf MEDIUM 6.1 The Sidebar Manager Light plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
1243c93c-d6ff-4353-bd14-ba0170caf580
< 10.0.22
MEDIUM 6.1 The SpecFit-Virtual Try On Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versi… wordfence
← Prev 996 997 998 999 1000 1001 1002 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top