🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 782 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f1111095-adaa-427c-b5e5-c0926c442180 MEDIUM 6.1 The Aklamator INfeed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'instagram_username' p… wordfence
f10fd22e-a25b-4f16-ad65-a995559908e9 MEDIUM 6.1 The Mocho Blog theme for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.0.4 due to … wordfence
f10a49ae-d58f-4244-ba10-330e04c1946e MEDIUM 6.1 The CropRefine plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
f0de5502-20a4-4436-89c6-ef42b8b40c08
< 2.0.0
MEDIUM 6.1 The Preview E-Mails for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the search_orde… wordfence
f0d96341-049c-4554-946b-12e2bf3e972e
< 1.1.1
MEDIUM 6.1 The Easy Digital Downloads (EDD) Wish Lists extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1… wordfence
f0cf53e3-1d5b-4f02-b1a1-61f6fc3ffe58
< 4.10.7.p
MEDIUM 6.1 A cross-site scripting (XSS) vulnerability in wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/… wordfence
f0936f5b-a0b2-466b-bb92-143db6c32456 MEDIUM 6.1 The Captain Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ctslider’ parameter in v… wordfence
f07957b3-27cb-4a5e-a8bb-2bca72f8eecf
< 5.4.9
MEDIUM 6.1 The Woffice Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
f063811b-9e1d-451d-beaa-a658b0876b95
< 1.4.11
MEDIUM 6.1 The oik-privacy-policy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
f06008c0-0ce3-4d78-934e-2a7fa5ce4e98
< 3.1.3
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to … wordfence
f05e5283-e9d9-44c8-9214-96dc18d94f7a
< 5.2.9
MEDIUM 6.1 The plugin PressForward for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameter in versions… wordfence
f05c7f89-2eb8-4172-b0bb-f5bc162c71cd MEDIUM 6.1 The Narnoo Commerce Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
f0520dd7-86f6-4218-84da-72620e28f010
< 1.1.5
MEDIUM 6.1 The SweetDate Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 1.1.5 due to i… wordfence
f04afca9-a03f-4390-9872-f744d0a86bec
< 0.2.2
MEDIUM 6.1 The Lazyest Backup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'xml_or_all' parameter f… wordfence
f04166e0-9f43-43ad-9552-618b81ab2d6f MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in cal/test.php in the ZdStatistics (zdstats) plugin 2.0.1 and earlier for Word… wordfence
f02237ab-c28d-431d-858d-44ea3b1ce2ee MEDIUM 6.1 The WPJobster theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.3.… wordfence
f01ecce1-cff1-41a6-ae90-3ace8b2e3a36
< 2.2.2
MEDIUM 6.1 The PDF Invoices & Packing Slips Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Sc… wordfence
f01618d8-85c8-4696-ab2e-cb6ac1b3530f MEDIUM 6.1 The Private Content plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
f01362dc-4f3d-4b77-b802-01b436287237
< 7.7.3
MEDIUM 6.1 The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in al… wordfence
efe898d3-56c2-4242-8416-49658ae2b8f6 MEDIUM 6.1 The Saoshyant Element plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
efe6c4aa-5e5d-4e3b-8a38-f85e163a9e00
< 1.6
MEDIUM 6.1 The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has XSS via a custom input field of a… wordfence
efe48adb-af9f-45dc-b693-ae56dce1bfe2 MEDIUM 6.1 The ArtiBot Free Chat Bot for WebSites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMess… wordfence
efd25f74-3c4a-4f5a-8c81-f1d42ca2a541
< 5.3.6.1
MEDIUM 6.1 The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas. wordfence
efca1ee2-2038-440e-941c-22533b4d833b
< 2.5
MEDIUM 6.1 The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
efba2017-67bd-40e0-a676-d043de361d08 MEDIUM 6.1 The User Language Switch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
← Prev 779 780 781 782 783 784 785 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top