πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1011 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
07a357f4-011e-45d3-bce3-6b5e38cada38 MEDIUM 6.1 The Product Excel Import Export & Bulk Edit for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site S… wordfence
07a0ffbe-bcc1-4686-bd91-a98cf1e2aeec
< 2.9.4.4
MEDIUM 6.1 The Uncode theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to 2.9.4.4 (exclusive)… wordfence
079f6ade-86b9-4fad-b739-5cb7aa69a740
< 5.1.4
MEDIUM 6.1 The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all vers… wordfence
079c77f1-3aab-4457-ad66-a2a2d9a55b2e
< 3.10.4
MEDIUM 6.1 The Posti Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the account_number and secre… wordfence
078ddf47-a17e-4359-8ea8-39e6d5267a0f MEDIUM 6.1 The Status Updater plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
078b58df-ca2f-4c44-896b-f0e0f7d3bf2b
< 6.1.13
MEDIUM 6.1 The Simple File List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up t… wordfence
077538e2-ef9a-490f-9188-31f9cb82aaf7
< 3.0.2
MEDIUM 6.1 The WP-BibTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0… wordfence
075e64fb-acaf-4f0f-bbc8-db7855184970
< 3.23.2
MEDIUM 6.1 The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using ext… wordfence
0753e172-3ff7-42a9-8651-d12573406d11
< 3.8.9.1
MEDIUM 6.1 The WP eCommerce plugin for WordPress is vulnerable to Cross-Site Scripting via the 'm' parameter in versions up to, and… wordfence
07534aa5-a7c4-4dc7-82ac-7e9c568f524c
< 2.1.10
MEDIUM 6.1 The WP Mail Catcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
074d8ccc-4fd6-4d46-9bc2-98d209f5a6a1 MEDIUM 6.1 The kvCORE IDX plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via any parameter on pages with the … wordfence
072fbfe7-37df-412e-bddb-68837473b3d6
< 1.1
MEDIUM 6.1 The Pool theme for WordPress is vulnerable to Reflected Cross-Site Scripting via PATH_INFO (PHP_SELF) in versions up to,… wordfence
0719db26-da88-4bda-ae83-f489591c8128 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to in… wordfence
0716471e-388c-43e5-abc3-84c78569e61a
< 2.8.3
MEDIUM 6.1 The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the searc… wordfence
070fd387-c0ca-47bf-a37a-530c1ffdb6ed
< 8.5.9
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in includes/admin/pages/manage.php in the Connections Business Directory plugin… wordfence
070f66ae-65aa-4670-8b69-103070a000a4
< 3.0.12
MEDIUM 6.1 The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'feed_id… wordfence
06fee60a-e96c-49ce-9007-0d402ef46d72 MEDIUM 6.1 The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to i… wordfence
06f56834-e1e9-4a02-988a-df4c563182c4 MEDIUM 6.1 The Ultimate Taxonomy Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includin… wordfence
06efdaff-2a03-4a08-bb74-1fae183c5842
< 3.19.5
MEDIUM 6.1 The WPPizza plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.19.… wordfence
06ef69f0-34d3-4389-8a81-a4d9922f1468
< 2.10.0
MEDIUM 6.1 The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versi… wordfence
06eaf73f-273c-4733-9ff9-2d8034221814
< 3.23.4
MEDIUM 6.1 The Stock Ticker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in the ajax_stockticker_load funct… wordfence
06d4a12c-9503-4e89-85e7-64838a42dc28 MEDIUM 6.1 The Blizzard Quotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
06d374b0-a4a6-4f0e-af85-66b3a50b1354
< 1.1.8
MEDIUM 6.1 The Portfolio Responsive Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parame… wordfence
06aa63ce-47f0-4095-ab5a-72c5dc6aabe3 MEDIUM 6.1 The Explore pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
0694b4f7-c28d-4456-8157-d20446790f3c
< 1.0.3
MEDIUM 6.1 The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has XSS. wordfence
← Prev 1008 1009 1010 1011 1012 1013 1014 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top