🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 786 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ecbb40a5-3e33-4084-a19b-daf014ce68c8
< 2.9.14
MEDIUM 6.1 The Affiliates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘newurl’ paramet… wordfence
ecaa02bf-62be-4f1d-af31-96afc72a830d MEDIUM 6.1 The Gixaw Chat plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
ec9a771f-bd55-4b64-8bb8-a5f795a7ab5d
< 1.1.7
MEDIUM 6.1 The WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerabl… wordfence
ec8a7e8c-225e-4d68-9219-942a8bf0a861 MEDIUM 6.1 The Notifications Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
ec86085a-a4a4-4ff7-ac2a-8330f3d96344 MEDIUM 6.1 The WP Admin Custom Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
ec7a97c4-62d5-44e7-a28b-350ecf9ecf66
< 3.8.3
MEDIUM 6.1 The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all ver… wordfence
ec6ea63d-60de-4b3f-8b7c-cbd951c3f737
< 1.7.3
MEDIUM 6.1 The WangGuard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'userIP' parameter in version… wordfence
ec55a952-113d-43e4-aa82-5c3dc984b24a
< 1.1.1
MEDIUM 6.1 The SmartLink Dynamic URLs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
ec53446d-00a5-48d3-b1f0-15cd05a9bd28 MEDIUM 6.1 The NewsBoard Post and RSS Scroller plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
ec51f8e4-dba6-44e7-876b-2be58df19b8d MEDIUM 6.1 The Shortcode Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
ec4d807b-7119-40f0-99a8-5df8471c515b
< 0.9.70
MEDIUM 6.1 The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before… wordfence
ec46ab73-8429-4cfc-8867-1ee1db22b43c MEDIUM 6.1 The W3SPEEDSTER plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7… wordfence
ec2da093-9f36-44c5-948b-590fd99734e8 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the qTranslate plugin 2.5.39 and earlier for WordPress allows remote attacke… wordfence
ec2825b2-c8df-40fd-b44d-a840be66446f MEDIUM 6.1 The Mediciti Lite theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versio… wordfence
ec084ade-d2e7-4484-8381-a83b04c41059 MEDIUM 6.1 The RSVPMaker Excel WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SE… wordfence
ec015f49-cdb6-4a08-81cd-6fa505086537
< 7.4.3
MEDIUM 6.1 The customer-area plugin before 7.4.3 for WordPress has XSS via admin pages. wordfence
ebf9760d-b7c2-43c7-bfb0-dde96de3dcb9 MEDIUM 6.1 The Brisk Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions d… wordfence
ebf84c6a-fd6c-4113-91ff-27c7564cabdb
< 1.9.7
MEDIUM 6.1 The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum… wordfence
ebd6c526-bd9d-4959-9929-c38334c21506
< 2.8.5
MEDIUM 6.1 The Awesome Event Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
ebd5b868-93f2-4517-9400-fd730b36434a MEDIUM 6.1 The SpatialMatch IDX plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
ebd42227-1cc2-42ab-b64b-3fe3fe1880c8 MEDIUM 6.1 The HTML5 Video Player with Playlist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'theme… wordfence
ebd1c1c0-0eb4-430d-a65b-9bf30a7dd52a MEDIUM 6.1 Multiple cross-site request forgery (CSRF) vulnerabilities in the DandyID Services plugin 1.5.9 and earlier for WordPres… wordfence
ebcbb7bf-99fd-4a74-a4d3-eabf9edcadc4 MEDIUM 6.1 The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Varia… wordfence
ebbee05c-fd32-4dd9-99d3-716ba604b859
< 0.0.33
MEDIUM 6.1 The AnyComment plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.0.32 due t… wordfence
ebb347a8-a8d2-4809-bfa5-772ad0de90f6 MEDIUM 6.1 The WP Projects Portfolio with Client Testimonials plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
← Prev 783 784 785 786 787 788 789 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top