🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 787 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ebb33fdc-fd89-4d4f-9107-287a64abc150
< 5.174.1
MEDIUM 6.1 The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQ… wordfence
eba81d49-7af5-4031-aa0e-43c2fa61cd38
< 3.1.0
MEDIUM 6.1 The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up … wordfence
eba7ab33-bcb6-4ada-ae5f-0df758fc719a
< 6.0.7
MEDIUM 6.1 The "Awesome Support – WordPress HelpDesk & Support Plugin" plugin for WordPress is vulnerable to Reflected Cross-Site… wordfence
eb9590b4-0d38-4e7f-944f-ee1c262fd805
< 2.5.0
MEDIUM 6.1 The ICDSoft Reseller Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
eb828160-b537-4435-9d85-47e0d70a6704
< 1.69
MEDIUM 6.1 The Remove tabs and fields from WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in vers… wordfence
eb767f64-b247-4d4f-99d9-fc0c54616944 MEDIUM 6.1 The Wibstats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … wordfence
eb6613ad-1fb2-4278-adc1-fe5d1ade3ad5
< 4.9.2
MEDIUM 6.1 The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Reflected Cross-Site Scri… wordfence
eb613de8-d298-471f-b585-2da3b5500f10
< 7.2.1.727
MEDIUM 6.1 The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fv_player… wordfence
eb60e5c8-cbda-4488-816c-a7fdf2b39fd6
< 3.4.22
MEDIUM 6.1 The Branda – White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cros… wordfence
eb60c1eb-9260-4fb8-a740-c6a4f8fcaf82 MEDIUM 6.1 The Random Featured Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
eb5398a8-840d-4d08-b03d-b5edded7ba64
< 3.8.3.3
MEDIUM 6.1 The Pie Register Premium plugin for WordPress is vulnerable to Unauthenticated Cross-Site Scripting in versions up to 3.… wordfence
eb519441-2598-4907-8e49-036c455176ad
< 12.0.10
MEDIUM 6.1 The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_refer… wordfence
eb49e8d5-1f4f-46d1-8206-0a43b4284f19 MEDIUM 6.1 The My Chatbot plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versi… wordfence
eb40f948-1252-4b6d-8c2d-3eb0e1f08987
< 1.7.2
MEDIUM 6.1 The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-group-id param… wordfence
eb3b3d65-70ee-4c9e-9e2f-18afc7368bbd
< 1.0.4
MEDIUM 6.1 The e-shopsカート2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
eb3a7623-ced8-4738-8a95-a3eda7e86ec1
< 1.4.8
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in readme.php in the April's Super Functions Pack plugin before 1.4.8 for WordP… wordfence
eb3817f6-b630-4dfe-90d5-a96673bb8a85
< 9.1.1
MEDIUM 6.1 The Contact Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
eb360c56-e144-4dc5-8bfb-715a014cb8e6 MEDIUM 6.1 The Reactflow Visitor Recording and Heatmaps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… wordfence
eb35b27f-e938-4a51-b441-887d23b7082a
< 5.5.3
MEDIUM 6.1 The Photo Gallery by Ays plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
eb329862-8cfa-49a5-b9cb-908acc4182e3
< 5.1.27
MEDIUM 6.1 iThemes Builder Theme Market before 5.1.27 for WordPress has XSS via add_query_arg() and remove_query_arg(). wordfence
eb2f39fe-b498-42ee-8614-e05acb2b2cde
< 1.4.0
MEDIUM 6.1 The ImmoToolBox Connect plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
eb2cda13-4fc8-4158-9462-db20fb0965bd
< 0.21
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Podcast Channels plugin 0.20 and earlier for WordPress allows remote att… wordfence
eb1b6443-31b4-4ee6-a827-fe749a48383f MEDIUM 6.1 The Simple Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
eb14896f-7f0e-4168-8a2d-309bbaddbedc
< 3.1.3
MEDIUM 6.1 The Wishlist for WooCommerce: Multi Wishlists Per Customer PRO plugin for WordPress is vulnerable to Reflected Cross-Sit… wordfence
eaf66cf7-c010-4785-bde0-a82ff7809fb1 MEDIUM 6.1 The Advanced Tag Lists plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
← Prev 784 785 786 787 788 789 790 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top