πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 781 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f25f358b-f9b7-4660-8dda-673023dc1967
< 1.5.5
MEDIUM 6.1 The Child Theme Creator by Orbisius plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions… wordfence
f25cdb02-4624-4a46-a622-28665e1d856e MEDIUM 6.1 The Amazon Link WordPress plugin through 3.2.10 does not sanitise and escape some of its settings, which could allow hig… wordfence
f257bb6a-442d-4475-b2d0-e97b540cd2c0 MEDIUM 6.1 The Activity Reactions For Buddypress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions u… wordfence
f23e7274-45f6-46da-b4c8-2eaa1bd39257
< 20.0.6
MEDIUM 6.1 The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Reflect… wordfence
f2268be8-f9b8-4028-b681-7793b2bd43f8
< 4.7
MEDIUM 6.1 Reflected Cross-Site Scripting (XSS) vulnerability in WordPress Ivory Search plugin (versions <= 4.6.6). Vulnerable para… wordfence
f2244c29-9d79-47d5-b077-bf04a9199cdc
< 5.9.8
MEDIUM 6.1 The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing the… wordfence
f219b6ea-58b9-455e-a99d-8412661c8e39 MEDIUM 6.1 The postMash – custom post order plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜m’ … wordfence
f216abf6-3883-4978-8ddb-f3f24cb40f26
< 2.0.0
MEDIUM 6.1 The SC Simple Zazzle plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
f214fd49-abf7-4c66-9ad2-a5da209c22df
< 4.1
MEDIUM 6.1 The Stylish Google Sheet Reader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
f20fc354-e93c-4da4-8344-a71b07e04e56 MEDIUM 6.1 The AdsPlace'r – Ad Manager, Inserter, AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scr… wordfence
f20b79cd-4393-4c96-ac78-139ac7c11144
< 1.1
MEDIUM 6.1 The o2s gallery plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 1.0 due… wordfence
f203fb35-e217-4912-aa80-0bb6b3de1830
< 2.3.7
MEDIUM 6.1 The Easy Digital Downloads (EDD) Free Downloads extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x befo… wordfence
f1f81d9b-87b5-4164-b472-e846421f121e MEDIUM 6.1 The Wp Custom CMS Block plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
f1f75927-34c6-4086-86e8-abbf921f3423 MEDIUM 6.1 The FWD Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
f1de8404-5c7b-48d7-ab7f-7f99b309ee43 MEDIUM 6.1 The timelineoptinpro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜id’ parameter in … wordfence
f1d82500-c679-49c7-aa6e-3ca9ef73fee9 MEDIUM 6.1 The WP Odoo Form Integrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
f1a8bdfb-b89c-4474-9568-bdfc75bcd5ab MEDIUM 6.1 The iONE360 configurator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
f18b7523-fa8f-4c5d-acd7-db0e2135c796
< 3.2
MEDIUM 6.1 The Product Enquiry for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' … wordfence
f160f474-de8d-4120-9f46-a185b035a627
< 1.0.16
MEDIUM 6.1 The Team Circle Image Slider With Lightbox WordPress plugin before 1.0.16 does not sanitize and escape the order_pos par… wordfence
f1420ec8-55e4-448d-8230-228d1e566b97 MEDIUM 6.1 The JustClick registration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
f127f028-79dd-4671-b789-01c56b77a70e
< 3.2.3
MEDIUM 6.1 The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
f124b5a0-b58b-45ff-bd22-7a09a9abd9bd MEDIUM 6.1 The Social Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2… wordfence
f122cba9-a6f8-46dd-90c5-c54311f2be7f MEDIUM 6.1 The Jigoshop – Store Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
f117fffb-2bbb-4e95-b589-909972db1e5e
< 3.8.0
MEDIUM 6.1 The Language Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a… wordfence
f11187da-21f8-4db5-aa36-1010f191e331
< 4.2
MEDIUM 6.1 The ARPrice - WordPress Pricing Table Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all… wordfence
← Prev 778 779 780 781 782 783 784 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top