πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1002 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
102a90a7-da55-44df-9d3f-111637bf131e
< 3.2.15
MEDIUM 6.1 The Ultimate Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
10207866-6615-486b-a60a-a522ed8a0285
< 7.6.2
MEDIUM 6.1 The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Refl… wordfence
101451de-1ed4-4717-86c5-a41feafd4c7e
< 4.5.4
MEDIUM 6.1 The WP-Appbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versi… wordfence
100cc190-d274-45d2-804d-78390816e5f0 MEDIUM 6.1 The Nino Social Connect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
100b700f-8812-48be-8a04-28f60a57b35f
< 5.6.5
MEDIUM 6.1 The Enfold - Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an u… wordfence
10019db4-a408-4441-895b-2c8bfe3fc92e
< 1.2.9
MEDIUM 6.1 The Gutenberg Blocks – Unlimited blocks For Gutenberg plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
1000c6db-800f-4f10-976b-5b946d5cc174
< 2.6.19
MEDIUM 6.1 The Foliopress WYSIWYG plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
0ff464d0-7aa4-4a79-a8d2-ea51398c40f9
< 1.1.0
MEDIUM 6.1 The SMTP by BestWebSoft plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.0… wordfence
0feaff52-062f-45d3-bece-b2c78bdd720e
< 2.2.1
MEDIUM 6.1 The WP 2FA WordPress plugin before 2.2.1 does not sanitize and escape a parameter before outputting it back in an admin … wordfence
0fe79ca5-2811-44eb-a340-a41383f9d42e
< 1.9.32
MEDIUM 6.1 The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an at… wordfence
0fe5a834-487e-4da8-8b30-384427e26e6b
< 5.6.0
MEDIUM 6.1 The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
0fd1cbbe-68b8-4a19-aea9-1e943d97c9c3
< 1.2.8
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Banner Effect Header plugin before 1.2.8 for WordPress allows remote att… wordfence
0fc2c20a-8927-4234-be08-1122e2a13a85
< 2.6.3
MEDIUM 6.1 The Variable Inspector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
0fc2b6cb-cca1-4d90-a229-12ec9d1f4b8b
< 7.1.05
MEDIUM 6.1 The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS. wordfence
0fc19c02-6dc0-4d4b-82fd-c72653d890dc
< 1.1.8
MEDIUM 6.1 The CRM Perks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1… wordfence
0fb1a2c2-581d-47ed-a180-9f70fdf79066
< 1.15.31
MEDIUM 6.1 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Refle… wordfence
0fb13522-95d7-428a-bbc6-e278f814e863
< 1.9
MEDIUM 6.1 The WP GeoNames plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
0fac8e7a-7379-4c0c-8c05-a8af1e37850c MEDIUM 6.1 The AllInOne - Banner Rotator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
0fa0b67b-edc8-4f91-bf67-167df63cf7bd
< 1.0.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the BuddyPress Extended Friendship Request plugin before 1.0.2 for WordPress… wordfence
0f9ab443-212e-4904-baf6-7eaa9d9370ea MEDIUM 6.1 The e-Boekhouden.nl plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
0f86e1ef-c898-4a54-8204-a9ec4caab586
< 1.0.5
MEDIUM 6.1 The WordPress Importer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
0f835e7c-f921-449d-9ffc-dd0fd141119d
< 26.0.7
MEDIUM 6.1 The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or S… wordfence
0f803e16-7f47-4696-927f-450aaa5fda5e
< 1.13.22
MEDIUM 6.1 The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did n… wordfence
0f7f91f6-9fe6-4bbf-ba3c-380ba2e97dcd
< 3.0.9
MEDIUM 6.1 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
0f77d41a-8b72-412f-9560-267bc50f9aec
< 3.6.95
MEDIUM 6.1 The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
← Prev 999 1000 1001 1002 1003 1004 1005 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top