🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 774 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f9b6c62f-b53f-44f7-8fe2-22bac0074f9d
< 2.0.4
MEDIUM 6.1 The ultimate-member plugin before 2.0.4 for WordPress has XSS. wordfence
f9b1c96c-ab87-43a8-a3ac-17fea337b690 MEDIUM 6.1 The Tweeple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions … wordfence
f9ab89a5-bc01-446e-8cea-40544ddec4d4
< 1.1.0
MEDIUM 6.1 The Realty by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 1.1.0 d… wordfence
f9a24526-9f37-498e-b125-df4a0d23d2db
< 6.5.3
MEDIUM 6.1 The Intro Tour Tutorial DeepPresentation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… wordfence
f9900533-0724-445f-9d56-8a0422479448
< 1.7.1
MEDIUM 6.1 The Analytics plugin is vulnerable to multiple Cross-Site Scripting vulnerabilities in versions up to, and including, 1.… wordfence
f96d5694-b70a-46a5-b493-cfcb5ab93247
< 2.5.5
MEDIUM 6.1 The Chameleoni Jobs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
f9660aee-1069-4197-b166-12ea30f8fd0c MEDIUM 6.1 The Feedpress Generator – External RSS Frontend Customizer plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
f958ed28-0520-47c7-9b60-94e7c6504d20
< 2.3.1
MEDIUM 6.1 The Easy Digital Downloads (EDD) Recurring Payments extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x … wordfence
f946c5b9-a227-47bd-bae2-decbb5748436
< 3.15.0
MEDIUM 6.1 The Avada (Fusion) Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 3.15.0… wordfence
f93dcb51-1caf-4d63-a8f3-f6251dd0d19f
< 1.0.6.7
MEDIUM 6.1 The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Refle… wordfence
f93cdc4b-7ac3-428c-816e-d3b6499e6c8c MEDIUM 6.1 The WC Return products plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
f93aa003-5b8b-4836-af65-80df2f9fbdb6 MEDIUM 6.1 The Voting Record plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
f938571b-4fdb-45d4-a8a6-f4aedcc1cfd7 MEDIUM 6.1 The Category Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
f9259875-c63f-48ed-a3c8-4d6d0ffe8004 MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in admin/swarm-settings.php in the Bugs Go Viral : Facebook Promotio… wordfence
f91838e7-8192-455f-ae79-a8c7e7cc06e3
< 4.3.0
MEDIUM 6.1 The Captcha plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’ parameter in ver… wordfence
f90f5f35-ed84-4284-be21-15bfaf10175f
< 2.17.3
MEDIUM 6.1 The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back i… wordfence
f90a1ad8-70ba-43a3-91a0-3845cd02b3b1 MEDIUM 6.1 The GoogleDrive folder list plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
f906ee78-e30e-40af-ae06-597a7ea73018
< 1.5
MEDIUM 6.1 The FV Descriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
f8f8e436-2679-4ecb-831e-2b22dd99be32
< 2.0.1
MEDIUM 6.1 The Peter's Date Countdown plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S… wordfence
f8f86293-a32f-49a6-8c8c-d37354ab040a
< 5.4.9
MEDIUM 6.1 The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … wordfence
f8f1001e-d4e6-4681-beb2-16c4965b9007
< 4.0.0
MEDIUM 6.1 The Import from YML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
f8efd36a-e01c-4e95-b12a-d6a77c77e44d
< 3.2.0
MEDIUM 6.1 The Affiliate Links Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
f8e6beeb-5af9-4713-bf7f-2edc1ddaa12f
< 6.0.4
MEDIUM 6.1 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… wordfence
f8de9a0d-d199-4268-84d3-71830003b311 MEDIUM 6.1 The Mediabay - WordPress Media Library Folders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in a… wordfence
f8db6a27-111b-4e6d-966e-0af0833307b1
< 1.0.3.3
MEDIUM 6.1 The tweet-wheel plugin before 1.0.3.3 for WordPress has XSS via consumer_key, consumer_secret, access_token, and access_… wordfence
← Prev 771 772 773 774 775 776 777 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top