πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 771 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fca6ddae-df77-4636-bfe1-29e8726386d4 MEDIUM 6.1 The Snippy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.… wordfence
fca4040d-3c6c-4e31-9bed-d1b6bf5b2bed
< 7.1.14
MEDIUM 6.1 Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject… wordfence
fc9bd62c-0be2-4722-8d11-f7d3c68af7fc MEDIUM 6.1 The Hospital Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ver… wordfence
fc8b0944-f669-40d3-899b-d7f91b1a1fea MEDIUM 6.1 The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' paramete… wordfence
fc7b19c7-a850-4783-9f8b-e338e03998eb
< 5.13.8
MEDIUM 6.1 There are several endpoints in the Store Locator Plus for WordPress plugin through 5.12.3 that could allow unauthenticat… wordfence
fc787bba-d696-49b4-a734-ef5f81a7f494 MEDIUM 6.1 The Storyform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.6… wordfence
fc72e388-9ffc-4b99-8835-4b4b6ef46f95
< 1.4.7
MEDIUM 6.1 The moreAds SE plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.4.6 due to… wordfence
fc672bc6-3fb7-4e32-bbdb-1f0116872b55
< 4.3.4
MEDIUM 6.1 The RH Frontend Publishing Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
fc4f4a78-7224-4f58-a103-7ad4df0eb36e
< 3.0.6
MEDIUM 6.1 The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to t… wordfence
fc43e782-c3e3-4503-a1cb-13386cb5bf56
< 1.13.0
MEDIUM 6.1 The Post Status Notifier Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
fc40be19-9256-4c90-8438-b71b9481625d MEDIUM 6.1 Multiple cross-site request forgery (CSRF) vulnerabilities in the wpCommentTwit plugin 0.5 and earlier for WordPress all… wordfence
fc3d84f3-bd9d-40e6-bc88-90c840a928c0
< 1.4.2
MEDIUM 6.1 wordfence
fc3af81e-7fa3-43a0-a403-87a042253632
< 2.2.2
MEDIUM 6.1 The Bulk Price Update for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜pa… wordfence
fc240e5a-da4b-4705-9d10-14ae2804fdb7 MEDIUM 6.1 The Base64 Encoder/Decoder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
fc0d1427-d01e-4054-8ba7-59d6878cfbea MEDIUM 6.1 The Newsletter Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'token_type' p… wordfence
fc08e4cf-3964-406e-9046-420e749df4b5
< 8.3.5
MEDIUM 6.1 The WP VR plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via tab parameters in versions up to, and… wordfence
fc06ba09-9562-4d97-90ff-5464399feced
< 7.0
MEDIUM 6.1 The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Reflected Cross-… wordfence
fc06640e-3243-4369-bf1d-fb33f4d76ff7
< 1.1.5
MEDIUM 6.1 The Taboola Pixel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
fc060a36-7e51-4868-8179-d75e80cc6528
< 1.2
MEDIUM 6.1 The Check Pincode For Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
fbee8f75-6b02-4f85-9680-585646d61a1b MEDIUM 6.1 The Global Meta Keyword & Description plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
fbe4688e-19a4-412a-8fe3-167badcfafdf
< 1.9.0
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allow remot… wordfence
fbdf2216-82a9-4a89-8a18-9d5667b7d29d
< 4.2.4
MEDIUM 6.1 The Primer MyData for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
fbda7303-2393-438a-9305-5642975f0419 MEDIUM 6.1 The Shoutbox theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and output… wordfence
fbc3d194-9e55-4a3d-ac50-024a0b810a50
< 3.4.11
MEDIUM 6.1 The Post Grid Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
fbc393a6-8357-47b2-9abd-aa611b09eb1c
< 5.8.0
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in admin/google_search_console/class-gsc-table.php in the Yoast SEO plugin befo… wordfence
← Prev 768 769 770 771 772 773 774 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top