🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1003 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0f775cb9-5799-4f79-bab4-8936bfb1fad1
< 3.2.8.6.1
MEDIUM 6.1 The RestroPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3… wordfence
0f75c6bf-1b93-49d5-b5fb-e59b4e67432f
< 2.7.1
MEDIUM 6.1 The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
0f70407e-712f-4856-8edb-b0ad89b0bf50 MEDIUM 6.1 The WP Pricing Table plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
0f6fa9c6-8a2b-49ca-ad7f-3aa51d671422 MEDIUM 6.1 The SEO Link Rotator plugin for WordPress is vulnerable to Cross-Site Scripting via the 'title' parameter in versions up… wordfence
0f59baba-646b-4f47-9b0e-04cb8fdf0459 MEDIUM 6.1 The WordPress Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
0f57458b-0cd2-4958-8190-c89076771e86
< 3.31
MEDIUM 6.1 The VideoWhisper Video Presentation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'room_n… wordfence
0f4aa403-5a8e-4e4d-a009-3f7bfdc7ada3
< 2.0
MEDIUM 6.1 The Love Travel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting and Cross-Frame Scripting via the '… wordfence
0f461dea-3572-4abd-8cd2-c1e60fc233f7
< 4.14.2
MEDIUM 6.1 The YITH WooCommerce Product Add-Ons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up… wordfence
0f45738b-fff6-438e-8870-508c622c1752
< 3.4.4
MEDIUM 6.1 The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
0f42b2be-2a7d-470a-896d-6148e31e4cce
< 2.3.5
MEDIUM 6.1 The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all v… wordfence
0f325945-8394-4ff5-8868-2b1c464cd91f
< 7.6.5
MEDIUM 6.1 The YellowPencil Visual CSS Style Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… wordfence
0f2ebd89-d34f-4f08-9654-049355fdfa3f
< 2.0.13.1
MEDIUM 6.1 The WPCode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via tag filter links in versions up to, … wordfence
0f2371df-8ee0-4a26-a33d-337c129dc7d3 MEDIUM 6.1 The SEO Rank Reporter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘keyword_item’ an… wordfence
0f218010-8429-4a8a-b7f6-e45945a2a1ba
< 1.1.5
MEDIUM 6.1 The Mass Email To users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'entrant' parameter… wordfence
0f210f6b-091f-45bf-be1e-872db3ab7b59
< 2.8.20
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the Contact Form DB (aka CFDB and contact-form-7-to-database-exte… wordfence
0f1cce87-3e59-48c1-9d38-adaa739f20db
< 0.9.2
MEDIUM 6.1 The Realia plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 0.9.2 via the 'filter-id' param… wordfence
0f10c476-ce0c-4204-8f68-46c12dac1ade
< 1.0.1
MEDIUM 6.1 The Featured Posts by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catego… wordfence
0f0f50e0-7015-4f00-880b-6eb94961177f
< 1.1.1
MEDIUM 6.1 The Form Store to DB WordPress plugin before 1.1.1 does not sanitise and escape parameter keys before outputting it back… wordfence
0f09cb59-dbbb-48a3-aeac-377f6ec87b88 MEDIUM 6.1 The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Param… wordfence
0efff314-b14f-4af4-b225-ba7e41d01b2e
< 1.4.2
MEDIUM 6.1 Several Smash Balloon Plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via URLs in various version… wordfence
0ef7d891-0efa-45e5-ad16-2f34fc017c8f
< 1.2.4
MEDIUM 6.1 The ELEX WooCommerce Google Shopping (Google Product Feed) plugin for WordPress is vulnerable to Reflected Cross-Site Sc… wordfence
0ed8ee65-d910-42a4-b6de-3229346dc59e
< 3.7.19
MEDIUM 6.1 In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation. wordfence
0ed5a9c4-5148-4c3f-81fd-78bdde31f258
< 1.10
MEDIUM 6.1 The TFO Graphviz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wi… wordfence
0ed49e0d-3b8e-4add-a8e7-4cc1852ed7a6
< 3.9.0
MEDIUM 6.1 The Raptive Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
0ed40cd3-b0af-4276-9723-640ada7c6f86 MEDIUM 6.1 The Preloader by WordPress Monsters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up … wordfence
← Prev 1000 1001 1002 1003 1004 1005 1006 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top