🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1012 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0691cff0-86ed-47d3-9492-5ebc930d3eb7
< 3.9.2
MEDIUM 6.1 The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Cross-Site Scripting via LaTe… wordfence
06902ed3-5d36-47e1-9851-febd77ca966e MEDIUM 6.1 The Internal Links Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
067ce322-9d37-4d90-92f3-ca5ada591797 MEDIUM 6.1 The ADIF Log Search Widget plugin for WordPress is vulnerable to Cross-Site Scripting via the 'call' parameter in versio… wordfence
066e127f-9217-4b92-8c8c-0e3881c10cd4 MEDIUM 6.1 The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … wordfence
066c9327-6d72-41f9-895e-d14fe6471832
< 4.6
MEDIUM 6.1 The Export All URLs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'starting-point' and 'e… wordfence
066b3b77-7888-4037-b443-a3c6fb540cf7
< 3.2.7
MEDIUM 6.1 The sitepress-multilingual-cms (WPML) plugin 2.9.3 to 3.2.6 for WordPress has XSS via the Accept-Language HTTP header. wordfence
0654ddef-0a6e-4241-b226-947b5b0415b1
< 2.4.0
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the WP Media Cleaner plugin 2.2.6 for WordPress allow remote atta… wordfence
06549752-8808-467e-a383-51395ffaa614 MEDIUM 6.1 The URL Shortener | Conversion Tracking | AB Testing | WooCommerce plugin for WordPress is vulnerable to Reflected Cro… wordfence
065009f6-f568-4fbe-8efd-9ced1e3da54e MEDIUM 6.1 The Widgetize Pages Light and Widgets as Shortcodes plugins for WordPress are vulnerable to Reflected Cross-Site Scripti… wordfence
06362518-f2ee-485f-9e0e-1b1ada9c72db
< 6.0.0
MEDIUM 6.1 The HBLPAY Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … wordfence
063457b6-b02b-4f4c-b746-576b7b919e67
< 5.0.30
MEDIUM 6.1 The iThemes Builder Depot Theme before 5.0.30 for WordPress is vulnerable to reflected XSS via add_query_arg() and remov… wordfence
06334fad-eb1d-4abe-b183-a9e11eedd3d2
< 1.8.2
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in templates/default/index_ajax.php in the Rezgo Online Booking plug… wordfence
062d906d-5a6e-4180-a2f2-18411334b9a1 MEDIUM 6.1 The Autotitle for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
061eb5a2-2112-4379-8d10-1493a843c5f7
< 0.8.9
MEDIUM 6.1 The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
060dd6aa-0864-4357-9e78-bd7797af58a0
< 3.7.3.4
MEDIUM 6.1 The Groundhogg plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.… wordfence
05f40082-30ed-45f7-81d5-d5334a51fcea
< 1.5.3
MEDIUM 6.1 The WPC Order Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
05d86f94-1a1c-42d6-b0db-e19c5cbd1766
< 1.7.5
MEDIUM 6.1 The PDF & Print by BestWebSoft – WordPress Posts and Pages PDF Generator Plugin for WordPress is vulnerable to Reflect… wordfence
05d41013-4dd7-43f1-9b3b-e5ae8e7f91b6 MEDIUM 6.1 The WidgetKit Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
05c4d7e3-f8a8-4c11-b962-38922b0801f9
< 4.1.6
MEDIUM 6.1 The s2Framework plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘listview’ and 'format'… wordfence
05bb119f-06e4-4f56-afc8-0c5a25266b02 MEDIUM 6.1 The WP System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1… wordfence
059f0c64-efcc-4b79-81eb-b4ae9e3e2826 MEDIUM 6.1 The xmlrpc attacks blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
059e5358-6a29-4cae-96b4-23897797b367
< 1.19
MEDIUM 6.1 The underConstruction plugin <= 1.18 for WordPress echoes out the raw value of `$GLOBALS['PHP_SELF']` in the ucOptions.p… wordfence
058886bc-f7cf-48e0-80a8-66bb2a42bb09 MEDIUM 6.1 The Brookside theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4 … wordfence
0577200a-6565-4d2d-98f5-bffff972a61e MEDIUM 6.1 The Image Mapper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
0564a9a1-a767-4192-8cb0-65c6fc4d064d
< 4.62
MEDIUM 6.1 Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPr… wordfence
← Prev 1009 1010 1011 1012 1013 1014 1015 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top