🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 773 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
faa3eb51-fdee-443e-aacb-04900f609efd
< 4.6.0
MEDIUM 6.1 The WP Helper Premium plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to 4.6.0 (… wordfence
faa16751-6933-41e0-b4d2-0daedc5ec050 MEDIUM 6.1 The The Logo Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
fa9e4635-43f8-4f3c-b62c-628e74028f7e MEDIUM 6.1 The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to… wordfence
fa9ccf59-7022-4be4-b5da-b16fe911a8f1 MEDIUM 6.1 The NanoSupport plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0… wordfence
fa9bf653-5932-4a7b-a004-4d4b21c034a1 MEDIUM 6.1 The EMC2 Custom Help Videos plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
fa977e6c-6b9d-4fa8-99f3-566d6a71424f
< 3.4.7
MEDIUM 6.1 The Terms descriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_… wordfence
fa95b782-5ac6-4f9b-9865-e33f1bb7d187 MEDIUM 6.1 The Frontend Post Submission plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
fa6b3d83-0a00-4482-94a6-4f551f55a827 MEDIUM 6.1 The InFunding – Plugin for Charity & Crowdfunding Website plugin for WordPress is vulnerable to Reflected Cross-Site S… wordfence
fa5c5da8-b8e8-46fd-8b20-45ee296315dd MEDIUM 6.1 The WP Dream Carousel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up … wordfence
fa4f169a-8970-499d-ad25-028c0d1c9d56 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote a… wordfence
fa4bf7dc-07be-4397-957c-ef0c1d61b40a
< 1.0.4
MEDIUM 6.1 The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attr… wordfence
fa4675dd-2742-4353-a519-10332b8379b3 MEDIUM 6.1 The Comment Validation Reloaded plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
fa39debf-b2c0-4e85-bef9-90e1365f96f8
< 0.9.5.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the userphoto_options_page function in user-photo.php in the User Photo plug… wordfence
fa325b30-3799-41b4-bdb8-90f42a659511
< 1.10
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Antisnews theme before 1.10 for WordPress allows remote attackers to inj… wordfence
fa31e932-7fbf-4933-9747-bd7427db7f5d
< 1.4.2
MEDIUM 6.1 The Evergreen Content Poster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
fa098919-66ed-41e5-a5f9-291e1859e889
< 2.8
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the The Erudite theme before 2.8 for WordPress allows remote attackers to in… wordfence
fa05a758-56a0-49e0-868f-a5db27d877a8
< 5.4.9
MEDIUM 6.1 The Woffice theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘[function_or_param]’ parame… wordfence
f9f4c25e-6233-42f0-a968-16221ed86cf2 MEDIUM 6.1 The Webriti Custom Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
f9f3349e-de64-498e-bb82-5ceff1456265
< 5.2.3
MEDIUM 6.1 The wp-retina-2x plugin before 5.2.3 for WordPress has XSS. wordfence
f9e0c658-b37c-4780-9589-6def9e36539b
< 1.0.17
MEDIUM 6.1 The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the… wordfence
f9de946c-941a-41d7-b1c4-440b4fcec9b0
< 2.9.1
MEDIUM 6.1 The Theme Test Drive plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘install_theme’ pa… wordfence
f9dc401e-0247-4f49-8092-8841ea6c1f90
< 2.1.6
MEDIUM 6.1 wordfence
f9d4ac3d-08ec-4783-8ccd-d64ab07d5d7f
< 3.2.3
MEDIUM 6.1 The count-per-day plugin before 3.2.3 for WordPress has XSS via search words. wordfence
f9c9f8db-26e4-4f79-88a3-9be1f5772ebe MEDIUM 6.1 The SEO Title Tag plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
f9c3ab75-93fb-4c63-a430-61d02a031e46
< 1.0.62
MEDIUM 6.1 The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-ad… wordfence
← Prev 770 771 772 773 774 775 776 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top