🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 785 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ed9a6e27-c18f-4edf-b793-16021ebf0a6f
< 4.1.0
MEDIUM 6.1 The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections. wordfence
ed886fd6-7d8d-4b99-ad8e-e290ba6f32d9 MEDIUM 6.1 The WP-Hijri plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.… wordfence
ed866cda-2244-4172-a8bd-63005bbee4fc
< 1.1.9
MEDIUM 6.1 The Feed Them Gallery plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.8… wordfence
ed78a67c-e178-4efb-9b74-fbcfa544f737
< 3.5.6
MEDIUM 6.1 The Grand Spa theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.… wordfence
ed766000-557b-483b-9b86-c1cc6898abb7
< 1.5.6
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in pretty-bar.php in Pretty Link Lite plugin before 1.5.6 for WordPress allows … wordfence
ed74aebc-9d52-4fac-b308-97765db62d3d
< 0.91
MEDIUM 6.1 The formbuilder plugin before 0.91 for WordPress has XSS via a Referer header. wordfence
ed64d0ff-4f49-4c18-86ec-2c6fbd559d2e
< 3.3.7
MEDIUM 6.1 The Order Tracking Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the start_date and end_d… wordfence
ed61c037-a73c-477e-a5b5-3b4781cec130
< 1.2.4
MEDIUM 6.1 The Export Customers Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't' parameter in … wordfence
ed5d8b70-eb0e-4e5c-a68a-d9bff493c04c
< 0.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Trending theme before 0.2 for WordPress allows remote attackers to injec… wordfence
ed579468-c998-4bec-b3a5-01d0ff206d35
< 2.0.10
MEDIUM 6.1 The Tutor LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reset_key' and 'user_id' par… wordfence
ed4c5ffa-2474-45f5-900b-59e3c60c15bc MEDIUM 6.1 The Bulk Me Now! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'status' parameter in all … wordfence
ed43e0ee-0b0e-4367-ba33-a8f08fafcd33
< 4.0.2
MEDIUM 6.1 The contact-form-plugin plugin before 4.0.2 for WordPress has XSS. wordfence
ed42e29f-d263-43fc-b06e-b7aaaa7622f7
< 3.0.72
MEDIUM 6.1 The eCommerce Product Catalog plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘find_optio… wordfence
ed40b50b-7d70-4abf-8895-2bf891124bae
< 1.8.5
MEDIUM 6.1 The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page a… wordfence
ed2bb3e2-5002-4746-a4f8-b5d1752ccbbf MEDIUM 6.1 The Opal Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via checkout form fields in all ve… wordfence
ed0860db-0e1f-4929-90d5-ff2766ba71ad
< 3.9.3
MEDIUM 6.1 The WP eCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'add_query_arg()' and 'rem… wordfence
ed05cd81-ca21-41de-9b02-bd84498cd74e
< 1.0.13
MEDIUM 6.1 The Pago por Redsys plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'Ds_MerchantParameters'… wordfence
ecfcbb55-10ba-45d8-9b05-c08d0aeb7675 MEDIUM 6.1 The PeoplePond plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
ecf1dfb2-8140-45c0-b75c-10d1c1fdc07a
< 1.6.8
MEDIUM 6.1 The ARForms Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
ece7810c-a65d-421e-ad16-03e51eafeeb6
< 4.1.4.1
MEDIUM 6.1 The Uncanny Toolkit Pro for LearnDash plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions u… wordfence
ece1d9b6-39f7-4f79-9ce2-c2498c005f0f MEDIUM 6.1 The SpiderDisplay plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
ecddca6d-c977-47e8-a91c-7cf3f59f668b MEDIUM 6.1 The Flying Twitter Birds plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
ecdcad88-c926-490f-8e83-09d92ba080f8
< 3.7.28
MEDIUM 6.1 In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins. wordfence
ecd93c67-fe26-4ee5-af23-8c26b822dc60
< 1.3.2
MEDIUM 6.1 The WP Quick Shop plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
ecd48e2c-343f-4bae-9d9e-260d003ef87c MEDIUM 6.1 The Simple Amazon Affiliate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter… wordfence
← Prev 782 783 784 785 786 787 788 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top