ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 783 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
efb37c6a-e1a0-4960-b53a-858b22b6e706
< 1.0.9
MEDIUM 6.1 The "SagePay Server Gateway for WooCommerce" plugin before 1.0.9 for WordPress has XSS via the includes/pages/redirect.p… wordfence
efaf589c-a808-4263-9734-3b335b06e7ca MEDIUM 6.1 The WP Background Tile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
efa7ce77-45dc-4fe4-b759-c80f3f18c594 MEDIUM 6.1 The NextGEN Gallery Voting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
efa01956-7c03-4f0f-9054-6920013a2b32
< 6.19
MEDIUM 6.1 Cross-site scripting vulnerability in MaxButtons prior to version 6.19 and MaxButtons Pro prior to version 6.19 allows r… wordfence
ef9ba9ff-b979-40c9-bead-0d665ef92287 MEDIUM 6.1 The HM Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
ef96782e-d3a6-43de-bf6a-801bbe2e43ed
< 4.54
MEDIUM 6.1 The Hide My WP plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.53 due to … wordfence
ef91b68e-c4f2-4691-8daa-0ffa4d4ee96e MEDIUM 6.1 The 百度分享按钮 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
ef8a592a-8100-4347-8407-189ca2867c3b MEDIUM 6.1 The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could a… wordfence
ef828667-f241-4c5c-92a8-0a4f366e190f MEDIUM 6.1 The Abundatrade Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
ef80a076-98cb-42c1-8d7d-0a6b38d7bfc8
< 1.6.6
MEDIUM 6.1 The Country Selector Plugin is vulnerable Cross-Site Scripting. The payload executes whenever the user tries to access t… wordfence
ef7d7378-fa94-4964-916b-a41f69866d76
< 11.6
MEDIUM 6.1 The VS Contact Form plugin for WordPress may be vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_U… wordfence
ef6538e7-8cde-4c49-9965-0624a25ffe65
< 0.8.8.6
MEDIUM 6.1 The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_exclude_pag… wordfence
ef60f4c3-e38f-4f95-80cd-5e1f5512ebf5
< 3.9.7
MEDIUM 6.1 The Outdoor theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.9.6 … wordfence
ef52026b-1bfc-481c-8eb7-511d1910a35e MEDIUM 6.1 The Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
ef4a7a20-663e-4e6a-af23-e8a87b18521e MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow r… wordfence
ef3b11ef-c328-489e-8c12-331621a0327c
< 8.0.18
MEDIUM 6.1 The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term X… wordfence
ef20da8c-6baf-4c21-b249-65e0b8901469
< 0.10.0
MEDIUM 6.1 The Songkick Concerts and Festivals plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
ef14c7b4-8cad-4139-a170-42470202ec24 MEDIUM 6.1 The MOLIE WordPress plugin through 0.5 does not escape the course_id parameter before outputting it back in the admin da… wordfence
ef08c1ad-fc85-4154-8634-21c506436317
< 1.1.1
MEDIUM 6.1 The Easy Digital Downloads (EDD) QR Code extension for WordPress in versions up to, and including, 1.1.0, as used with E… wordfence
ef0866ea-1edd-4d45-b3b9-75a0244e8951 MEDIUM 6.1 The Tiki Time theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3 … wordfence
eee91d95-afdb-45e3-b639-50eb3c46115d
< 2.4
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress all… wordfence
eee87b71-713e-4e97-90a4-4ed71d264053 MEDIUM 6.1 The NativeChurch theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4… wordfence
eee27f2c-bc21-4b0f-9de5-da1035c54857
< 6.1.5
MEDIUM 6.1 The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Reflected Cross-Site S… wordfence
eedada2a-5543-46b1-a3d2-5e5b86a05ff9
< 4.0.0
MEDIUM 6.1 The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘… wordfence
eed6306a-317b-40ed-b7f5-7f930b3509e0
< 2.4.4
MEDIUM 6.1 The Conference Scheduler WordPress plugin before 2.4.4 does not sanitize and escape the tab parameter before outputting … wordfence
← Prev 780 781 782 783 784 785 786 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top