πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 766 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ffae2808-454e-4380-af83-b181cf2e8fbd
< 4.1.3
MEDIUM 6.1 The Popup box plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.2. … wordfence
ff9c424c-f37f-4c30-aa95-da597008cbb2
< 2.8.1
MEDIUM 6.1 The Recipe Card Blocks by WPZOOM plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the message pa… wordfence
ff986a66-93f7-4926-8818-7af745c0166c
< 1.25.10
MEDIUM 6.1 The Form builder to get in touch with visitors, grow your email list and collect payments β€” Happyforms plugin for Word… wordfence
ff8a629f-4a2f-474c-be22-82a0a3a9f4a5 MEDIUM 6.1 The Advanced Custom Fields: Link Picker Field plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ve… wordfence
ff7fe2bc-16bd-4ebc-b6f4-cd32b2e55cfa MEDIUM 6.1 The Badgearoo plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
ff70f7aa-4c2c-4693-8b1f-d6e3ebbb0dad MEDIUM 6.1 The googmonify plugin through 0.5.1 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=… wordfence
ff6db316-6621-4f16-bf74-af6e75fa8609 MEDIUM 6.1 The WP Download Codes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
ff35d524-d97d-4fba-9f60-f40bb8aa2aa8
< 2.12.5.1
MEDIUM 6.1 The xili-dictionary plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
ff2855cb-e4a8-4412-af24-4cee03ae2d43
< 5.2.4
MEDIUM 6.1 The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… wordfence
ff2235b0-2960-4896-8665-ba34defb47e9 MEDIUM 6.1 The Visual Recent Posts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
ff210859-a65f-494f-a2bd-36b7ff92dec0
< 6.5.1
MEDIUM 6.1 The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 6.5.1 (… wordfence
ff1c1aea-2374-4fb8-98d2-7d0cf72eff59
< 1.9.6
MEDIUM 6.1 The Arconix FAQ plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
ff0950ae-46d3-4070-b7d3-ec075df634bc
< 3.5.8
MEDIUM 6.1 The Grand Magazine theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
ff08a391-971b-4c78-80e0-1d72a3ae5f1c
< 1.4.3
MEDIUM 6.1 The Norse Rune Oracle Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
ff06c6f3-1dd7-4b4e-bd13-4e41f2198bf2 MEDIUM 6.1 The Metro theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.13 due… wordfence
fef2f3fd-d6a3-4cb5-af5f-3fad8a67ca9c
< 1.9.2
MEDIUM 6.1 The Jobeleon WPJobBoard theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
feef7934-c10d-48a7-a5dc-33e603e1d402
< 5.1
MEDIUM 6.1 The WPMU Ldap Authentication plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
fedb49da-ac10-4ead-9ee1-38aa5fc3b5ff MEDIUM 6.1 The WP Simple Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
fed101af-dd1a-486b-bc6b-a10452ec39ab MEDIUM 6.1 The RT-Theme 18 Responsive WordPress Theme plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versi… wordfence
fecb12c5-8f8d-4f72-a349-c5df315b523e MEDIUM 6.1 Cross-Site Request Forgery (CSRF) vulnerability leading to Reflected Cross-Site Scripting (XSS) in CalderaWP License Man… wordfence
fecac276-20be-4ce6-b819-c1747e059bf4 MEDIUM 6.1 The Goo.gl Url Shorter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
fec6deaa-c45e-40f5-91e9-87445c94a61a MEDIUM 6.1 The Broken Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
feb3a274-05f9-4f01-b4dc-f63aa98ff4dd MEDIUM 6.1 The Drop Caps plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1… wordfence
feb25e04-8cd2-49d8-a459-4302c1ec332c MEDIUM 6.1 Multiple cross-site request forgery (CSRF) vulnerabilities in the Timed Popup (wp-timed-popup) plugin 1.3 for WordPress … wordfence
feaa2809-c804-4a21-8f5e-8149b2d490d4 MEDIUM 6.1 The Shipdeo plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1… wordfence
← Prev 763 764 765 766 767 768 769 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top