🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1013 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
062d906d-5a6e-4180-a2f2-18411334b9a1 MEDIUM 6.1 The Autotitle for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
061eb5a2-2112-4379-8d10-1493a843c5f7
< 0.8.9
MEDIUM 6.1 The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
060dd6aa-0864-4357-9e78-bd7797af58a0
< 3.7.3.4
MEDIUM 6.1 The Groundhogg plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.… wordfence
05f40082-30ed-45f7-81d5-d5334a51fcea
< 1.5.3
MEDIUM 6.1 The WPC Order Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
05d86f94-1a1c-42d6-b0db-e19c5cbd1766
< 1.7.5
MEDIUM 6.1 The PDF & Print by BestWebSoft – WordPress Posts and Pages PDF Generator Plugin for WordPress is vulnerable to Reflect… wordfence
05d41013-4dd7-43f1-9b3b-e5ae8e7f91b6 MEDIUM 6.1 The WidgetKit Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
05c4d7e3-f8a8-4c11-b962-38922b0801f9
< 4.1.6
MEDIUM 6.1 The s2Framework plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘listview’ and 'format'… wordfence
05bb119f-06e4-4f56-afc8-0c5a25266b02 MEDIUM 6.1 The WP System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1… wordfence
059f0c64-efcc-4b79-81eb-b4ae9e3e2826 MEDIUM 6.1 The xmlrpc attacks blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
059e5358-6a29-4cae-96b4-23897797b367
< 1.19
MEDIUM 6.1 The underConstruction plugin <= 1.18 for WordPress echoes out the raw value of `$GLOBALS['PHP_SELF']` in the ucOptions.p… wordfence
058886bc-f7cf-48e0-80a8-66bb2a42bb09 MEDIUM 6.1 The Brookside theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4 … wordfence
0577200a-6565-4d2d-98f5-bffff972a61e MEDIUM 6.1 The Image Mapper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
0564a9a1-a767-4192-8cb0-65c6fc4d064d
< 4.62
MEDIUM 6.1 Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPr… wordfence
055a891b-ee05-431f-aaff-612b3fd1513d
< 6.5.1
MEDIUM 6.1 The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
0551bd2d-b196-4382-be33-07319c2e1614 MEDIUM 6.1 The ePermissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
054f6ed4-75fc-4431-9249-48f41860d682
< 0.9.7
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Content Cards plugin before 0.9.7 for WordPress allows remote attackers … wordfence
0549acd5-686b-4505-af68-f3f854096f63
< 2.0.4
MEDIUM 6.1 Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attacker… wordfence
05131b5d-3837-4679-920b-8fadf74a69c9
< 1.2.3.3
MEDIUM 6.1 The Easy Digital Downloads (EDD) Recommended Products extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.… wordfence
050f1c42-7635-41f4-a2b2-97461b5070c8 MEDIUM 6.1 The FLX Dashboard Groups plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
04ffc248-2b5c-4c64-8bfd-361a8ff6a8af MEDIUM 6.1 The Category Post List Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
04f1f701-4793-4783-a274-19688fff181e MEDIUM 6.1 The kStats Reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
04ef55ed-6aa3-488e-b233-acc44502ae5f
< 1.2.1
MEDIUM 6.1 The DN Shipping by Weight for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versio… wordfence
04c00e94-11fc-4d43-8e9d-9de719b72616 MEDIUM 6.1 The LIVE TV plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2 d… wordfence
04afce48-88a0-4d46-af19-a534f89f70d7
< 1.5
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in compfight-search.php in the Compfight plugin 1.4 for WordPress allows remote… wordfence
04a99e67-6af2-43c5-a21b-052eb683945c
< 1.3.6
MEDIUM 6.1 The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back… wordfence
← Prev 1010 1011 1012 1013 1014 1015 1016 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top