🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 778 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f59ccb78-722b-490b-874e-7026afc3511b
< 1.6.3
MEDIUM 6.1 The SKU Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of… wordfence
f5925251-302a-4132-80ea-21ebc0c65944 MEDIUM 6.1 The JNews - Frontend Submit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
f5867f37-ae58-4f75-828e-bb99b3e5252e
< 1.0.4
MEDIUM 6.1 The Currency Switcher for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use … wordfence
f57ee188-2fdf-402f-b712-80de0d6f7f8d
< 4.2.1
MEDIUM 6.1 The Device Detector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
f5733a60-8078-48ed-9395-ea79b4199f7e
< 1.0.21
MEDIUM 6.1 The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from lo… wordfence
f5698128-f76d-4be4-8d5a-fb465b202d52 MEDIUM 6.1 The MJ Contact us plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
f5500911-52cf-43b5-a15e-e8db5bedd5af
< 2.18.2
MEDIUM 6.1 The Real Cookie Banner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_… wordfence
f5442453-6b72-4c8b-8b9f-59b8536aac73
< 1.3.7.3
MEDIUM 6.1 The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it … wordfence
f53a22a3-d3c2-44c4-8e66-a9775b69b147 MEDIUM 6.1 The Varnish WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
f52f6d55-d0f5-4eba-bc07-ed94bded8777
< 1.4.14
MEDIUM 6.1 The Sabai Discuss plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in version… wordfence
f5281d4b-c2cd-4972-b837-e101a8893c6e
< 1.38.3
MEDIUM 6.1 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflecte… wordfence
f52285e0-e78d-4231-8ff9-53fbe568fcc2
< 1.0.7
MEDIUM 6.1 The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… wordfence
f4ff957a-1969-48f5-9f4e-d6bee2cbe581
< 1.2.0
MEDIUM 6.1 The Right Click Disable OR Ban plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
f4eb46c8-77fe-4e47-9912-5d8fd4ec0918 MEDIUM 6.1 The UW Freelancer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
f4e8ad18-fa25-414c-8a94-9ad9bd3c2e31
< 2.3.7
MEDIUM 6.1 The XO Event Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘selected-name’ p… wordfence
f4d41f7f-f0c6-4e50-bf5f-37ee25415f43
< 2.0.20
MEDIUM 6.1 The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to Multiple Reflected Cross-Site Scripti… wordfence
f4bf4e12-5cbb-45bc-938e-62163baaa15d
< 1.1.10
MEDIUM 6.1 The Thumbnail carousel slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term p… wordfence
f4b69cff-31ac-4abe-8f03-07ee3fb4c285 MEDIUM 6.1 The MoolaMojo WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the classes parameter found in the ~/… wordfence
f4acd261-d924-46d5-8aef-49b026cba8ca MEDIUM 6.1 The EZPZ One Click Backup plugin for WordPress is vulnerable to Cross-Site Scripting via the 'mail' parameter in version… wordfence
f49cafe0-2caf-4148-b7c9-1b78bbfba6e7 MEDIUM 6.1 The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising… wordfence
f497c9b0-afd4-48b8-a701-b2a9ad2b4389 MEDIUM 6.1 The Asynchronous Javascript plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
f48bb7d9-ce82-4549-aead-2876dd3081a8 MEDIUM 6.1 The 3D Avatar User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
f4835539-a66c-4d14-b3c3-9a3a64e89ea6
< 1.3.8.5
MEDIUM 6.1 The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not escape the wpacu_selected_sub_tab_area pa… wordfence
f47d38d2-d388-4a79-a47b-af41cd85e404 MEDIUM 6.1 The Border Loading Bar WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `f` and `t` parameter fo… wordfence
f478a5b3-58ef-410e-801f-82eaa579941a MEDIUM 6.1 The WP Service Payment Form With Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via … wordfence
← Prev 775 776 777 778 779 780 781 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top