🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 777 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f6710f53-34fe-4549-9e1a-7826be74c912
< 2.7.6
MEDIUM 6.1 The Jobs for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘job-search’ par… wordfence
f654390a-7a1a-4948-a624-2df99e15c103
< 1.4
MEDIUM 6.1 The VikRestaurants Table Reservations and Take-Away plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
f6522041-74a0-4703-ab1e-20621c231f1a MEDIUM 6.1 The Twitter real time search scrolling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … wordfence
f64fd871-d9fd-446a-b59a-0c4d8b23c9f1
< 1.1.3
MEDIUM 6.1 The ReviewsTap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
f6440661-0646-4ec1-b4c9-5e80390d8565 MEDIUM 6.1 The Predict When plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
f6433a17-0017-46a9-a8e6-4d4a4a55f2db
< 1.4.8
MEDIUM 6.1 The WP Search Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘render_stats_pag… wordfence
f63bed1e-b5b1-4c95-9304-8656fa7176e9
< 3.5.0
MEDIUM 6.1 The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vul… wordfence
f62a486a-137b-48e5-b276-44438958e811
< 3.1.23
MEDIUM 6.1 The FULL – Cliente plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_ar… wordfence
f629fc93-84ce-4c33-b1c0-3a3194aac477
< 1.5.103
MEDIUM 6.1 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected C… wordfence
f62713c9-bf87-44be-9b7e-c088989bad77
< 5.3.2
MEDIUM 6.1 The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the multiple parameters in … wordfence
f625b10b-f104-49a8-9dbb-f880f5df8693
< 1.4.2.3
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin before 1.4.2.… wordfence
f61bda49-1eb0-49a3-8af1-8cadf088464f
< 1.5.5
MEDIUM 6.1 The WP Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mes' parameter found in th… wordfence
f618911f-fd03-41ec-a0e1-dba4aa7178ab
< 2.6.1.3
MEDIUM 6.1 The Post Views plugin for WordPress is vulnerable to Cross-Site Scripting via the 'search_input' parameter in versions u… wordfence
f61321d4-477a-4f4d-bed2-4ae6fdb864a9 MEDIUM 6.1 The Custom List Table Example plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
f611d609-97c5-4b77-9657-c8d9d10e786a MEDIUM 6.1 The IP Metaboxes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'metabox' parameter in ver… wordfence
f60fef0e-5b2d-4672-ab3d-21e4b6708f4a
< 1.1
MEDIUM 6.1 The Custom Website Data plugin for WordPress is vulnerable to Cross-Site Scripting via the 'ref' parameter in versions b… wordfence
f60a97df-c98a-4980-bc57-50147c87dd91 MEDIUM 6.1 The my-related-posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
f5f43242-cbf6-42a0-b9c0-d67b8f8b25af MEDIUM 6.1 The ULTIMATE VIDEO GALLERY plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
f5ec709c-c67d-4067-a118-166e104d148a
< 1.0.5
MEDIUM 6.1 The Help Center by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
f5ea3e03-fafa-431e-b1fe-a527f491da79
< 4.0
MEDIUM 6.1 The VR-Frases (collect & share quotes) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several … wordfence
f5c9fc19-fc91-44d1-b6a5-a1ec0d6dbfe8 MEDIUM 6.1 The User Meta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.1… wordfence
f5af155b-b65e-4cb1-a748-fc0fc5c6176d
< 8.2.7
MEDIUM 6.1 The Website LLMs.txt plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all… wordfence
f5a827b1-7f66-4a24-9e31-c3f3e36b4772 MEDIUM 6.1 The Google Maps in Posts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘icon’ paramet… wordfence
f5a71d0a-e00f-4794-acc2-834334d5b336
< 3.5
MEDIUM 6.1 The Easy Social Share Buttons for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via several param… wordfence
f5a54d1d-3593-4ba1-a747-651278488be6 MEDIUM 6.1 The Special Feed Items plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
← Prev 774 775 776 777 778 779 780 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top