πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 776 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f7b6b59a-366f-4fa6-9e54-01372d6cea8c MEDIUM 6.1 The ImmoPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerable OAut… wordfence
f799db97-ca61-439d-94ec-a44270d1cd07
< 1.7.5
MEDIUM 6.1 The Import Eventbrite Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' paramet… wordfence
f7968054-69f1-47f5-9a32-b124ee1133ce MEDIUM 6.1 The Associados Amazon Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
f78e6faf-ff1d-4944-aa54-7843cc8614f4
< 3.3.0
MEDIUM 6.1 Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attacker… wordfence
f787e299-21f8-4662-935a-ff1e25c7d275
< 0.9.4
MEDIUM 6.1 The Gmedia Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
f7857dad-a843-4e5e-9994-41d025b8a5ac
< 1.7.61
MEDIUM 6.1 The Encyclopedia / Glossary / Wiki plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions … wordfence
f773ef2f-c33d-414e-9c2f-df22b9d00234
< 1.1.51
MEDIUM 6.1 The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes… wordfence
f75966a5-e593-4c86-842d-c136ae847eb0
< 2.2.6
MEDIUM 6.1 The Post Timeline for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.5 … wordfence
f74c419a-56de-4190-925d-876d32f712e1
< 3.2.2
MEDIUM 6.1 The Compare Products for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜s_f… wordfence
f74c392c-1d79-4498-8298-d1160af250b6 MEDIUM 6.1 The go Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0… wordfence
f7485859-c155-4335-aa76-3b4363dbbe4c
< 1.7.8
MEDIUM 6.1 The Web Directory Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
f745d10e-9a03-4461-b981-189d4ad3b0a6 MEDIUM 6.1 The Kumihimo plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … wordfence
f7350dc3-82a0-4f61-9ff8-4b622108fa06
< 3.37
MEDIUM 6.1 The Qwiz Online Quizzes and Flashcards plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the qnam… wordfence
f70d0bea-3ac2-4235-92a2-09458b85bddd
< 6.4.2.7
MEDIUM 6.1 The Quiz Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.… wordfence
f70b66ad-55fb-45f8-944a-2c8712071113
< 1.25.0
MEDIUM 6.1 The Ultimate Addons for Beaver Builder plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and… wordfence
f6fe59e8-78cf-47f4-90eb-920f8e4fd204
< 1.3
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in admin/partials/uif-access-token-display.php in the Ultimate Instagram Feed p… wordfence
f6e3e5dd-b9f1-4d24-98cc-b6ab319434e4
< 1.6.8.5
MEDIUM 6.1 The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to R… wordfence
f6db5e9f-9b3b-44c9-a6d9-78df3ed3b1fc
< 1.3.8
MEDIUM 6.1 The Stop User Enumeration plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1… wordfence
f6d24786-676b-478a-ad9a-5c3f5ca3e85b MEDIUM 6.1 The Scarlet theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions due to the inclusion of … wordfence
f6c7b969-04e4-409a-81e2-823a94701d41
< 7.7.1
MEDIUM 6.1 The ANAC XML Bandi di Gara plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
f6c211bb-c7e6-41d3-8cbc-45a286bffc9e
< 1.0.40
MEDIUM 6.1 The Wishlist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … wordfence
f68c8953-7441-4204-b1e8-8c49cf491d34 MEDIUM 6.1 The Footer Flyout Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
f682b623-f9c5-44ce-90db-c6ee4c27a93b
< 3.0.9
MEDIUM 6.1 The Customer Reviews Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_debug_code' par… wordfence
f67c4315-b73d-4eac-8ded-0e5b3a937fec MEDIUM 6.1 The MercadoLibre Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
f6754c9a-81e1-4b39-a125-5293ee4ff758
< 6.1.2
MEDIUM 6.1 The YOP Poll WordPress plugin before 6.1.2 does not escape the perpage parameter before outputting it back in an attribu… wordfence
← Prev 773 774 775 776 777 778 779 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top