🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1314 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6da00adc-8fc0-4d8f-9ff3-8c21223199f4 MEDIUM 4.4 The Scroll post excerpt plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
6d8f59b0-da92-43aa-990d-5271aa40d6b4
< 1.6.83
MEDIUM 4.4 The AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable plugin for WordPress is vulnerable to S… wordfence
6d571dcc-74a4-4380-8961-890f10443b80
< 0.2.2
MEDIUM 4.4 The WP-CORS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Allowed domains’ admin settin… wordfence
6d1517d4-79d0-4d4b-b54d-86e00dabd874
< 3.1.29
MEDIUM 4.4 The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti… wordfence
6ce24fa7-b265-4689-94b3-7df62c7074c2
< 3.0.7
MEDIUM 4.4 The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.0.7 due to insuf… wordfence
6cc218fb-6c2a-4676-b2d7-86abe01c1530
< 2.1.49
MEDIUM 4.4 The Direct checkout, Add to cart redirect for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
6ca2311c-7b44-4dad-bea0-131776205319 MEDIUM 4.4 The Multi Rating plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions u… wordfence
6ca08679-6aed-46c5-823c-6144112eed02
< 2.3
MEDIUM 4.4 The Side Cart Woocommerce (Ajax) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… wordfence
6c7871b8-6364-4821-891e-5c809c7bc4d5 MEDIUM 4.4 The QuickieBar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
6c50edbb-1da5-4261-8bb8-2ef0b66fe602
< 1.5.2
MEDIUM 4.4 The VikRestaurants Table Reservations and Take-Away plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
6c098b35-606e-4dde-8683-4c90f518ddb5
< 9.3.0
MEDIUM 4.4 The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video Embed parameter in a… wordfence
6be26c07-cac4-42d8-becb-03045a54cd6c
< 1.4.6
MEDIUM 4.4 The Protected Posts Logout Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i… wordfence
6bcbdf6f-770c-4496-a643-94dbf63e893a
< 3.4.0
MEDIUM 4.4 The WP Staging (Free <= 3.3.3, Pro <= 5.3.3) plugins for WordPress are vulnerable to Stored Cross-Site Scripting via adm… wordfence
6bbd5e03-2b66-463c-96aa-fc6b44b4f03c MEDIUM 4.4 The Checkout Field Editor for WooCommerce – Checkout Manager plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
6b8f64ed-abf8-4a8b-b32f-75afeaccea5c
< 1.2.1
MEDIUM 4.4 The Novelist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via certain book information fields in ve… wordfence
6b5e9c7f-e0c9-4c27-8b39-87e15fd29604 MEDIUM 4.4 The Quick Call Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio… wordfence
6b16028a-0b69-422b-9471-32ea6edb93a0
< 1.1.2
MEDIUM 4.4 The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… wordfence
6b0382e2-e029-4e19-981c-6dc570e182f0
< 1.3.0
MEDIUM 4.4 The WholeSale Products Dynamic Pricing Management WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
6b028923-82fe-4dd6-af77-69d7744f2812
< 3.0.7
MEDIUM 4.4 The Easiest Sales Funnel Builder For WordPress & WooCommerce by WPFunnels plugin for WordPress is vulnerable to Stored C… wordfence
6ac72136-7911-4980-92b0-9bf18bed2201
< 3.1.6
MEDIUM 4.4 The WP Adminify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … wordfence
6ab7bd94-f0cd-4ff1-a642-8317165cdbaf
< 1.2.4
MEDIUM 4.4 The Novelist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.3 d… wordfence
6a99dade-815e-43cf-be24-92c01286f476
< 2.6.0
MEDIUM 4.4 The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
6a830fb8-de5f-40c7-bb6c-464ed916b440
< 1.21.1
MEDIUM 4.4 The My WP Customize Admin/Frontend plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
6a76b224-9b55-4294-8a04-44c94a3115f7
< 3.0.4
MEDIUM 4.4 The avalex – Automatisch sichere Rechtstexte plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
6a765360-8603-4ba1-a6db-dd0175ff3ddf
< 1.2.91
MEDIUM 4.4 The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings… wordfence
← Prev 1311 1312 1313 1314 1315 1316 1317 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top