πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 779 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f460d529-f15e-4c23-ad67-94d3f4bc0c2e
< 2.2.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are us… wordfence
f45afce1-cb37-4e7e-90b2-6ae1b6400376
< 3.6.8
MEDIUM 6.1 The affiliate-toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up … wordfence
f44fdbb2-abb8-488f-bdc0-ec6eea93d92a MEDIUM 6.1 The wp Time Machine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
f4460f0a-9417-48bf-b6b3-27a80632dd71
< 2.7
MEDIUM 6.1 The WPB Show Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
f4454376-7c18-4f0e-a192-80212a59d94b MEDIUM 6.1 The Push Notifications for WordPress by PushAssist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
f43b5c02-fb10-48f1-9457-f67c5008fe5b MEDIUM 6.1 The Innovs HR plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0… wordfence
f4366cf8-bf50-4d9f-9a85-2c2de7f7e90d
< 1.4.3
MEDIUM 6.1 The Action Network plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in ve… wordfence
f4232656-2e97-4888-8dde-14039d8c2f9d
< 3.6.0
MEDIUM 6.1 The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a… wordfence
f4211712-26b2-4f59-82b8-928e405cd08d
< 1.11.3
MEDIUM 6.1 XSS exists in the the-holiday-calendar plugin before 1.11.3 for WordPress via the thc-month parameter. wordfence
f4143849-1cd1-4241-acf6-a34aaf7d369c MEDIUM 6.1 An issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. Persistent XSS can occur … wordfence
f40dd50f-fa64-4901-990c-42e9db53c081 MEDIUM 6.1 The My Custom Widgets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
f40c6e22-ef6c-4a5f-85df-97fd36c57f82 MEDIUM 6.1 The En Masse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0 … wordfence
f3ff44f2-c3c2-46f5-b984-6151202f722f
< 4.2
MEDIUM 6.1 The Dreamstime Stock Photos plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
f3fc6230-043f-4079-a82a-1b5d191dbf7d MEDIUM 6.1 The Affiliate Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
f3fc1686-06a0-4d48-bb79-470e63cd3600
< 1.2
MEDIUM 6.1 The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter. wordfence
f3e94ba2-ffdd-42ac-86bf-48670f2087e5
< 2.54
MEDIUM 6.1 The Butcher theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and excluding, 2.54 d… wordfence
f3d990ef-5fa8-455d-b35a-2bff82facd45 MEDIUM 6.1 The Send email only on Reply to My Comment plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … wordfence
f3d535b3-ad52-4322-988e-7d560dbfe3a3
< 3.7.1
MEDIUM 6.1 The Raptive Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'poc' parameter in all vers… wordfence
f3c5aafc-e75a-472e-9b62-10bb5a9da9b6
< 2.4.1
MEDIUM 6.1 The Contact Form 7 – Clockwork SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'to' p… wordfence
f3a4aeb2-3929-4f6b-ac6e-bccc1c3bf0dd
< 2.2.5
MEDIUM 6.1 The WP Statistics plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.2.4 due… wordfence
f389f4bf-ffff-4862-b4e2-4465ca0556ef
< 1.9.9
MEDIUM 6.1 The Helpie FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several URLs in versions up to, and… wordfence
f3855918-960e-487d-9d5f-6dbeba45523e
< 5.127.4
MEDIUM 6.1 The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The… wordfence
f37f6d9f-cd2d-421d-a5ac-ce552f0d0181 MEDIUM 6.1 The DL Leadback plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
f3781245-14b1-4b1c-a471-a5a413cdb2ed
< 4.2.8
MEDIUM 6.1 The NextScripts: Social Networks Auto-Poster plugin before 4.2.8 for WordPress has wp-admin/admin.php?page=nxssnap-repos… wordfence
f36ed435-3836-4c43-9e8c-ec07325e05d4 MEDIUM 6.1 The Fidelo Snippet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
← Prev 776 777 778 779 780 781 782 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top