🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 775 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f8b69e14-1c21-4f52-a1fb-6da34b00b1fd MEDIUM 6.1 The Defa Online Image Protector Free Edition plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… wordfence
f8b178ed-994b-4b2c-85b5-dada1059c600
< 1.7.7
MEDIUM 6.1 The MyMedi theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 1.7.7 due to insufficie… wordfence
f8a356db-02a2-4392-baca-46ef1bbfc801
< 0.10.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in diagnostics/test.php in the Social Connect plugin 0.10.1 and earlier for Wor… wordfence
f89373e8-2fef-427e-854b-8b78b5781288
< 1.5.0
MEDIUM 6.1 The MachForm Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
f88eaf82-e5de-43e2-b998-4a6d33be65ac
< 2.0
MEDIUM 6.1 The Parallelus Unite, Intersect, Traject, & Salutation Premium WordPress Themes for WordPress are vulnerable to Reflecte… wordfence
f88da532-31e5-4788-9b41-5ed4721ad6e0 MEDIUM 6.1 The LGPD Framework plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
f88aa3de-3204-4e92-bb19-41ff79f42168
< 3.2.26
MEDIUM 6.1 The pixfort Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
f8534891-2269-4afe-b83f-df512ca36456 MEDIUM 6.1 The WebARX plugin 1.3.0 for WordPress has unauthenticated stored XSS via the URI or the X-Forwarded-For HTTP header. wordfence
f849d0e8-2b08-41de-ac18-c8d6e98ffa83 MEDIUM 6.1 The offset writing theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
f83b36fe-4e46-4ab7-a113-6dcfa7cce625
< 8.4.2
MEDIUM 6.1 The Soledad theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 8.4.1 … wordfence
f8228b0d-be97-4e7c-8346-d203f7130958
< 1.5
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in compfight-search.php in the Compfight plugin 1.4 for WordPress allows remote… wordfence
f821bc5d-4590-4dfb-b709-73476a7eeac2 MEDIUM 6.1 The Multilang Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
f81af4b7-71e0-4fce-b0f9-530afed34922
< 1.1.5
MEDIUM 6.1 The Better WishList API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
f816edcc-f204-474d-a652-83114f5a4347
< 7.5.21
MEDIUM 6.1 The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions… wordfence
f815a4e5-cca2-4b86-96f4-ad956814d685 MEDIUM 6.1 Open redirect vulnerability in the proxyimages function in wowproxy.php in the Wow Moodboard Lite plugin 1.1.1.1 for Wor… wordfence
f810326f-f84a-4066-aa28-5caa915ba877
< 5.4.40
MEDIUM 6.1 The miniOrange's Google Authenticator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘us… wordfence
f80fef43-ffc4-4b9b-ae17-000d14281c43
< 4.8.0
MEDIUM 6.1 The Moloni plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.7.4 … wordfence
f80fcadd-d6b7-4d35-bced-ada3514e60fa
< 4.5.12
MEDIUM 6.1 The Store Locator Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘start’ paramete… wordfence
f80238dc-3caa-420b-92ee-27e690e9ead0
< 1.2
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in pay.php in the Pay With Tweet plugin before 1.2 allow remote atta… wordfence
f7f810f6-b8dd-4065-8113-9842b33202ef
< 1.7.0
MEDIUM 6.1 The Seriously Simple Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu… wordfence
f7f08d0a-b3ac-4363-ba6e-91a8e13605ca
< 3.5.6
MEDIUM 6.1 The Elementor Website Builder plugin for WordPress is vulnerable to Unauthenticated DOM-based Reflected Cross-Site Scrip… wordfence
f7dcf515-a476-4346-ba90-aa233fca6e59 MEDIUM 6.1 The Contact Form vCard Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
f7c93236-09d9-4e52-a96b-917d57d667f7
< 4.4.5
MEDIUM 6.1 The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
f7c095f7-f8aa-4b4d-841c-41b9850b5c62
< 3.2.2.0
MEDIUM 6.1 The Universal Video Player - Addon for WPBakery Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
f7c092f9-208f-404b-9680-ad77e80a0be6 MEDIUM 6.1 The Staging CDN plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
← Prev 772 773 774 775 776 777 778 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top