🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 780 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f36df17d-4633-42e0-b106-908b994d8cb7 MEDIUM 6.1 The Ultimate Endpoints With Rest Api plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page'… wordfence
f36af71c-78af-402c-9d3a-3752368e7584
< 14.0.0
MEDIUM 6.1 The Contest Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
f34f98a0-9df4-4b50-ae6a-7912e4b12bb2
< 1.9.20
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in lib/includes/auth.inc.php in the WPtouch plugin 1.9.19.4 and 1.9.20 for Word… wordfence
f34e397a-beaa-4c09-bedb-c41515d1adfa MEDIUM 6.1 The WP Cleaner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
f34b7518-5cb3-4b4e-8b18-927c08c045f7
< 1.6.7
MEDIUM 6.1 The Accounting for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad… wordfence
f34825a5-f7ef-42f8-8995-d41ab79b9082 MEDIUM 6.1 The Easy Post Duplicator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
f338b8a9-7b0a-46bd-b624-ebda897651f1 MEDIUM 6.1 The 10CentMail plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.… wordfence
f3158e77-39b3-4151-8f10-5824000a585a
< 1.3.6.4
MEDIUM 6.1 The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Sc… wordfence
f2fad774-f140-4891-8c6f-fbd684e19dc2
< 1.1.8
MEDIUM 6.1 The Montezuma theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the inclusion of a vulnerable v… wordfence
f2e6f09e-0ebc-47e3-84f3-9aede2781f42 MEDIUM 6.1 The GD Star Rating plugin for WordPress is vulnerable to Cross-Site Scripting via the 'wpfn' parameter in versions up to… wordfence
f2c6d446-75cd-4f42-a5f2-f4c59d4084ce MEDIUM 6.1 The House Manager – Easy Renter Management System for WordPress plugin for WordPress is vulnerable to Reflected Cross-… wordfence
f2bc0449-b5cc-403b-a943-f53d0d9c663a
< 1.1.0
MEDIUM 6.1 Manual Purchases Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg… wordfence
f2b70e27-87fb-4905-bbfa-62cca3dbb433 MEDIUM 6.1 The Laborator Xenon theme 1.3 for WordPress allows Reflected XSS via the data/typeahead-generate.php q (aka name) parame… wordfence
f2b4f946-036d-4136-81b8-a8cd2a68e097
< 2.2
MEDIUM 6.1 The NaturaLife Extensions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
f2a87cb3-5cce-4b5a-937d-71e96aeef7c9
< 3.2.3
MEDIUM 6.1 The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape … wordfence
f2a5d8ef-109c-471b-a135-c834f090eb5b
< 2.9.9
MEDIUM 6.1 The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before out… wordfence
f2a59015-eb29-44fe-bc21-ba8832ac750b
< 1.13.40
MEDIUM 6.1 The Form Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
f29a843d-a8c5-4477-b7cc-620b19b5f585
< 3.5.1
MEDIUM 6.1 The Clearpay Gateway for WooCommerce plugin is vulnerable to Reflected Cross-Site Scripting via the ‘orderToken’ par… wordfence
f294575d-ce83-4301-ae38-3f0761d9b610
< 2.0.15
MEDIUM 6.1 The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-ca… wordfence
f294175e-dfcd-4d8d-84ee-a945ec7ac7e3
< 2.3.2
MEDIUM 6.1 The soundcloud-is-gold plugin before 2.3.2 for WordPress has XSS via the wp-admin/admin-ajax.php?action=get_soundcloud_p… wordfence
f2888dcc-86f3-43a7-8c48-116e382d051f
< 1.1.8
MEDIUM 6.1 The CRM Perks Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
f281c9a5-1663-4dca-968f-685d933f99b1
< 3.3.0
MEDIUM 6.1 The Kudos Donations – Easy donations and payments with Mollie plugin for WordPress is vulnerable to Reflected Cross-Si… wordfence
f268974a-db92-42d2-9e1d-f990ea067740
< 1.4.2
MEDIUM 6.1 The Contact Form Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'formId' parameter… wordfence
f267527d-5fb5-4fc2-bb35-bc60854f1a68 MEDIUM 6.1 The WP Foodbakery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
f260495e-d62f-41c9-b6ac-ea015e17ee2f MEDIUM 6.1 The Aphorismus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
← Prev 777 778 779 780 781 782 783 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top