🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 770 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fd8a4296-8a6e-4455-8a69-87cace9199a9
< 3.0
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote … wordfence
fd78d162-d9aa-4623-9b89-5f1455739836
< 6.0.3.4
MEDIUM 6.1 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … wordfence
fd6b3ebe-a29b-4509-bb8c-d101073f21dc
< 1.1.10
MEDIUM 6.1 The two-factor-authentication plugin before 1.1.10 for WordPress has XSS in the admin area. wordfence
fd671562-adc8-40b0-af26-9daef70effa6 MEDIUM 6.1 The ScoreMe theme through 2016-04-01 for WordPress has XSS via the s parameter. wordfence
fd60fa87-d3da-4e3f-bd9b-b9d117bdbc4c
< 4.3.4
MEDIUM 6.1 The WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS. wordfence
fd54bedf-0bec-46ff-a555-c88eaa04068b MEDIUM 6.1 The Scheduled plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0… wordfence
fd46c8ee-975d-44d8-8083-e89c31c69aa7 MEDIUM 6.1 The WooCommerce Sales MIS Report plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
fd42b0f2-cb28-41b0-b8df-f7d06c273168 MEDIUM 6.1 The APK Downloader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
fd368b2c-ef40-453b-aeef-ad88d847c29b
< 1.6.1
MEDIUM 6.1 The Open Graphite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the topic parameter in versio… wordfence
fd24b087-83a7-4f9a-8f7a-1bd94332c1f7 MEDIUM 6.1 The WPLG Default Mail From plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S… wordfence
fd22babc-f1a9-4f50-9756-fe692105dca3
< 4.0.1
MEDIUM 6.1 The ARMember plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' parameter in ver… wordfence
fd21b3fb-656d-4060-b7c6-e0b8e79afb4c
< 1.5.6
MEDIUM 6.1 The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… wordfence
fd1b88bb-9b31-42e8-a826-b64abe2d41c4 MEDIUM 6.1 The sidebarTabs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3… wordfence
fd0c3965-6b35-46a8-8cf0-6726cdb03c8f
< 2.7.0
MEDIUM 6.1 The Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tag’ parameter in ve… wordfence
fd05991d-382b-460c-b89f-e1f7dfac9e60
< 2.6.1.4
MEDIUM 6.1 The SP Projects & Document Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and inc… wordfence
fcfe67fc-a59d-4660-b730-b97c1bebdfb7
< 2.9.9
MEDIUM 6.1 The WP w3all phpBB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
fcfe5129-854a-4dc0-a5ba-34b2ff38486e MEDIUM 6.1 The Terminal Africa plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
fcf005ba-2753-43f5-9f2b-24a8c59505c1
< 1.3.4
MEDIUM 6.1 The Skaut bazar WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] … wordfence
fcecd7bb-85cc-406e-9fd8-e671b327dc13 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in fonts/font-form.php in the Style It plugin 1.0 and earlier for WordPress all… wordfence
fcea4792-ca99-40ed-9bf0-0f5a523a47fd MEDIUM 6.1 The bbpress Simple Advert Units plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
fcce2857-5bc8-4bee-b218-45f56cb0184b
< 1.7.2
MEDIUM 6.1 Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary … wordfence
fcc21e14-30f4-474f-9740-0cb4fe110f70 MEDIUM 6.1 The Role Includer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_id’ parameter i… wordfence
fcbf81f8-8b33-4b83-91fb-626b7b5f3bb2 MEDIUM 6.1 The Top Position Google Finance plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['… wordfence
fcb6b1c6-19ba-46e5-9999-532ec8facc92 MEDIUM 6.1 The Rankchecker.io Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
fcae647f-7eed-4ecd-83b8-482b55b86ec9 MEDIUM 6.1 The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET par… wordfence
← Prev 767 768 769 770 771 772 773 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top