🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 772 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fbc14a5f-fa6b-47fa-8e8b-502409b18ed6
< 1.2.9
MEDIUM 6.1 The WP Popup Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
fba24935-5bab-4395-b05e-7bb5d5a1694d
< 15.3
MEDIUM 6.1 The WP Content Copy Protection & No Right Click (PRO) plugin for WordPress is vulnerable to Open Redirect in all version… wordfence
fb892e06-b32c-4cea-92e5-e214acb91a2f
< 1.2.7
MEDIUM 6.1 The smokesignal plugin before 1.2.7 for WordPress has XSS. wordfence
fb878e2d-3573-4a70-9968-c0cf9676056d MEDIUM 6.1 The DTC Documents plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1… wordfence
fb7e922a-fae0-46f9-b8c1-0986b88f2813
< 13.2.0
MEDIUM 6.1 Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a pl… wordfence
fb7e7083-59b6-498a-ab02-e578cdf17b1f MEDIUM 6.1 The Teleport plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.… wordfence
fb726242-84fb-47f3-ac43-b43b5b4ae7f0
< 3.10.2
MEDIUM 6.1 The Sina Extension for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
fb587e37-473a-4e46-afe3-8285af0fa0d0 MEDIUM 6.1 The Spiritual Gifts Survey (and optional S.H.A.P.E survey) plugin for WordPress is vulnerable to Reflected Cross-Site Sc… wordfence
fb518425-56e0-4a8c-ac51-3c9b2c047f11 MEDIUM 6.1 The WP Social Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
fb4cefe4-a95f-4a80-a8b4-02a3c0d56795 MEDIUM 6.1 The WP Custom Post RSS Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
fb33f779-d045-48dd-babe-8b1fab903124 MEDIUM 6.1 The Wishful Blog theme, versions up to and including 2.0.1, and Raise Mag theme, versions up to and including 1.0.7, for… wordfence
fb2fffb1-cc8c-46a4-b3ea-2b1aac684fbd MEDIUM 6.1 The Atahualpa theme for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, and in… wordfence
fb1f22c2-fdb3-4e3c-b6d5-2e933ec889bd
< 1.4.8
MEDIUM 6.1 The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS. wordfence
fb1dbbec-c8c0-4934-ba07-b5b188886bac
< 2.0.0
MEDIUM 6.1 The RTMKit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'themebuilder' parameter in all … wordfence
fb0d093b-c339-4b19-a6cd-d2589b8e57ff
< 1.2.104
MEDIUM 6.1 The WooCommerce PDF Invoice Builder, Create invoices, packing slips and more plugin for WordPress is vulnerable to Refle… wordfence
fb0b24b6-38da-4650-b542-a31ba8c98fb9
< 2.3.1
MEDIUM 6.1 The "Donation Plugin and Fundraising Platform" plugin before 2.3.1 for WordPress has wp-admin/edit.php csv XSS. wordfence
fb0971cf-f4f6-4e41-9e99-c2ba193e39df
< 1.5
MEDIUM 6.1 The Connect Contact Form 7 to Constant Contact plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in v… wordfence
fae793f2-8cb5-49d3-9c8c-2a8377552fcd MEDIUM 6.1 The Cazamba plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1… wordfence
fac1e55f-7027-494d-8beb-9a23e0fc2e00
< 10.6.7
MEDIUM 6.1 The Wp EMember plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'editrecord' parameter in al… wordfence
fabeeba6-f3c0-4f9c-a12f-c97801aad810
< 2.8.1
MEDIUM 6.1 The NPS computy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'data1' and 'data2' paramet… wordfence
fabd576c-6990-40a1-9a94-ecb63e2b0189
< 2.0.7
MEDIUM 6.1 Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPr… wordfence
fabcfaee-54b5-409f-b023-71aebdda2e00
< 1.4.8
MEDIUM 6.1 The Jaroti theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 1.4.8 due to insufficie… wordfence
faafa3d3-a4b7-40a5-9133-c953f921ba55 MEDIUM 6.1 The WP IMAP Auth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
faad9cf7-5d83-4ade-b121-c38fb0de78a5
< 4.7.1
MEDIUM 6.1 The Poll Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.… wordfence
faa6c744-7586-47ee-b2ce-af972ee8b4f7
< 2.8.3
MEDIUM 6.1 The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_href’ parame… wordfence
← Prev 769 770 771 772 773 774 775 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top