🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1040 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6f7e632f-eada-4a3f-9e92-ba00c6aa503e
< 3.2.4
MEDIUM 5.5 The WP Word Count plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.… wordfence
6f782dd7-df49-4c3b-b6d9-de618ab32b87
< 2.0.0
MEDIUM 5.5 The Gettext override translations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘validcons… wordfence
6f6f8412-f1b1-4566-ad31-f006c19de948
< 1.3.0
MEDIUM 5.5 The Cyklodev WP Notify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in ver… wordfence
6f0a332f-b761-44b3-86e8-82411455ba3e
< 12.6.6
MEDIUM 5.5 The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page i… wordfence
6ef70f07-ef60-4842-91a9-879478d3f4d2
< 2.1
MEDIUM 5.5 The Kunze Law WordPress plugin before 2.1 does not escape its 'E-Mail Error "From" Address' settings, allowing high priv… wordfence
6ef48df5-dc3f-45d2-87af-35a3a0ed8c2d
< 3.5.1
MEDIUM 5.5 The 404s WordPress plugin before 3.5.1 does not sanitise and escape its fields, allowing high privilege users such as ad… wordfence
6e53e70f-45fc-41a6-8436-a8b14f7685d0
< 1.7.20
MEDIUM 5.5 The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the fields label in … wordfence
6db9c59e-16bc-4e61-9040-7000b212675f
< 1.9.9
MEDIUM 5.5 The Tutor LMS WordPress plugin before 1.9.9 does not escape some of its settings before outputting them in attributes, w… wordfence
6d4544b9-bb15-47e2-b377-0bae91aba4da MEDIUM 5.5 The 3com – Asesor de Cookies plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
6c3f4796-3496-4786-9afb-bd32827764ff
< 1.5.9
MEDIUM 5.5 The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high… wordfence
6c240829-0672-4ac2-b49a-2068a0a549f1 MEDIUM 5.5 The WordPress Auction Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
6bf7a5c3-f30d-42d6-91f9-8eb11089a499
< 1.2.29
MEDIUM 5.5 The Gallery – Photo Albums (formerly titled Easy Media Gallery) Plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
6bdd1817-7248-48fa-8d2f-00e777bf1257
< 3.1.0
MEDIUM 5.5 The Comment Edit Core – Simple Comment Editing plugin for WordPress is vulnerable to Server-Side Request Forgery in al… wordfence
6b5964a7-410b-4fea-9de2-22ffda80c8e8
< 8.5.6
MEDIUM 5.5 The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to SQL Inject… wordfence
6b2e61aa-617b-450e-8859-50b1012fc0c3
< 1.1.0
MEDIUM 5.5 The JobBoardWP WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sa… wordfence
6af83daa-ad8c-43ba-b77e-ad085889277c
< 3.7.31
MEDIUM 5.5 WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer. wordfence
6abde5cf-9335-4ce0-a95f-94c5c29fd207
< 4.12.1
MEDIUM 5.5 The Ajax Search Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
6a595b3c-2b21-43fe-8d4e-6721f4541c9b MEDIUM 5.5 The Automatic Youtube Video Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set… wordfence
6a44a55e-a96a-4698-9948-6ef33138a834
< 2.88.0
MEDIUM 5.5 The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘templates[browsingpage][t… wordfence
69cf2f28-33ae-441e-95d2-01d187c7745a
< 3.3.1
MEDIUM 5.5 The WordPress Auto Upload Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameter… wordfence
69971673-e317-452c-8c54-97de006a214f
< 1.19.0
MEDIUM 5.5 The HTTP Headers plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.1… wordfence
6972f776-993c-4e5f-b347-5c784c42601c
< 2.0.5
MEDIUM 5.5 Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Feather (WordPress plugin) versio… wordfence
69693a9a-fc9e-49ea-8c41-438ee6af7ee8
< 0.8.8
MEDIUM 5.5 The Event List WordPress plugin through 0.8.8 does not sanitise and escape some of its settings, allowing high privilege… wordfence
6935bca8-ad64-4c55-9cf0-c7dd088d8c0c
< 2.0.0
MEDIUM 5.5 The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is re… wordfence
6904f168-e06f-4f17-905b-a943a39dfbdb
< 1.6.7
MEDIUM 5.5 The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to Server-Side Request Fo… wordfence
← Prev 1037 1038 1039 1040 1041 1042 1043 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top