🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 767 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fea1546c-1d8f-4478-81b7-20a9096e0217 MEDIUM 6.1 The WP Image Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'file' parameter in a… wordfence
fe848a09-edd3-4eea-befb-909d15ba1994
< 1.36.1
MEDIUM 6.1 The Hubbub Lite – Fast, free social sharing and follow buttons plugin for WordPress is vulnerable to Reflected Cross-S… wordfence
fe799030-ec9c-45fd-a5a9-6589364b6056 MEDIUM 6.1 The DT Chocolate theme plugin for WordPress is vulnerable to Cross-Site Scripting in all versions due to insufficient in… wordfence
fe71e2b9-ddd7-4d6d-97e5-5fad41f8f35c
< 2.0.0
MEDIUM 6.1 The Unilevel MLM Plan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter … wordfence
fe679ff6-6ade-48fa-8699-6a96da49f8c8
< 1.6.8
MEDIUM 6.1 The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable t… wordfence
fe5f7aaf-46e3-4d62-ae3f-85bbb85a511d MEDIUM 6.1 The Causes – Donation Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
fe54c37f-1421-48aa-b502-045847d13ae3
< 1.1.16
MEDIUM 6.1 The WP Responsive Tabs horizontal vertical and accordion Tabs plugin for WordPress is vulnerable to Reflected Cross-Site… wordfence
fe46ec14-4795-4ac7-afd0-de92ccef877d MEDIUM 6.1 The weichuncai(WP伪春菜) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
fe2a538b-60a5-4595-b901-4477679e6b8a
< 1.5.63
MEDIUM 6.1 The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter. wordfence
fe274dc5-3999-4fa6-88a8-57aecbb6f4c1
< 1.1.5
MEDIUM 6.1 The MemberPress Discord Addon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
fe18de26-ef1e-44bc-94ed-eb9ddab15331
< 6.1.3
MEDIUM 6.1 The Course Booking System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
fe0e4729-bf06-481c-8ea2-5fab8e8a417f
< 1.0.13
MEDIUM 6.1 The sequel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.… wordfence
fe086290-f3d3-4d28-bb5c-11fbbb1364b4
< 2.8.52
MEDIUM 6.1 The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflan… wordfence
fe025d8f-3a68-4d69-89ea-62b3113c267e MEDIUM 6.1 The Forms: 3rd-Party Post Again plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
fe023bc0-11b9-4520-874a-4656f633d4ac
< 1.9.27
MEDIUM 6.1 The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthent… wordfence
fdf6d876-631f-493d-a324-3bb8efedd84a
< 1.2.2
MEDIUM 6.1 The WP Hardening – Fix Your WordPress Security WordPress plugin before 1.2.2 did not sanitise or escape the historyval… wordfence
fdf6b2ea-5a6a-481b-9431-650c895f54ef
< 2.1
MEDIUM 6.1 The Binary MLM Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page’ paramet… wordfence
fdc1289a-abd1-43db-89b7-3e81878a0f9a
< 1.0.25
MEDIUM 6.1 The ProductDyno plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘res’ parameter in all … wordfence
fdb822e8-583e-4437-a735-b116aa8886e2
< 2.4.1
MEDIUM 6.1 The WP-Optimize plugin and SrbTransLatin plugin for WordPress are vulnerable to Cross-Site Scripting via the 's' paramet… wordfence
fdb6c326-bd48-440a-9eba-7073b6a68844 MEDIUM 6.1 The FrescoChat Live Chat plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
fda7ad16-d66b-47fc-bbd6-18fd0b1c1e03 MEDIUM 6.1 The WP PT-Viewer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
fda1be79-ba45-4e8f-bfc3-355f9cdbad82
< 6.2.7.0
MEDIUM 6.1 The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable t… wordfence
fd8cafa4-594e-47e5-9a1b-666a5b23feea
< 2.5
MEDIUM 6.1 The Simple Membership Custom Messages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versio… wordfence
fd8a4296-8a6e-4455-8a69-87cace9199a9
< 3.0
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote … wordfence
fd78d162-d9aa-4623-9b89-5f1455739836
< 6.0.3.4
MEDIUM 6.1 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … wordfence
← Prev 764 765 766 767 768 769 770 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top