🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 788 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
eaebcae4-cdf5-4eb7-9246-07185fe62d07 MEDIUM 6.1 The Protección de Datos RGPD plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
eae14ac7-ebc1-45a1-b0dd-fec2bbb14460
< 2.0.2
MEDIUM 6.1 The Website Toolbox Community plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘websitetoo… wordfence
eacaf990-c825-4d9b-91dc-18f6ef5caf6f
< 1.1.6
MEDIUM 6.1 The Content Snippet Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
eac8685b-8ed9-432d-8912-b66bd62c950f
< 2.0.11
MEDIUM 6.1 The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Script… wordfence
eab729ed-ec00-4be1-a738-fce8a4f26100
< 1.3.0
MEDIUM 6.1 Membership Add-on for iThemes Exchange before 1.3.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). wordfence
eaaf1ac0-1ea6-4bcb-a385-87267525801c
< 3.3.1
MEDIUM 6.1 A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute ar… wordfence
ea9ca8ac-e735-4e84-af0f-45d22a8e2124
< 1.5.3
MEDIUM 6.1 The Smart Maintenance Mode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘setstatus’ … wordfence
ea82e978-a653-4ae3-94aa-bc77b94a176c
< 1.5.49
MEDIUM 6.1 The PropertyHive plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘date_post_id’ paramet… wordfence
ea7d643c-3388-469f-b4a9-5c68341e2af0
< 2.5.7
MEDIUM 6.1 The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via unescaped URLs in… wordfence
ea7b85fd-b771-4af3-bdcb-d976fa7bd8fc MEDIUM 6.1 The ECT Add to Cart Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
ea6eac9c-988c-4cd2-be68-ff2a2ceb86e4 MEDIUM 6.1 The Scan External Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
ea5c1fa7-1838-4a5b-ac56-df2184ff9cc8 MEDIUM 6.1 The Accessibility Task Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
ea5c0b48-7e8e-492e-b0de-14681e31fe85 MEDIUM 6.1 The Custom Post Type to Map Store plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
ea3b6fa6-1b58-40c2-8ec2-8a9211069f11
< 7.8.3
MEDIUM 6.1 The FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress is vulnerable to Refle… wordfence
ea24cb9e-88a5-45a2-93f8-544afef5a83b
< 3.1.1
MEDIUM 6.1 wordfence
ea189072-aa96-441b-ad5e-b6433da06d22
< 1.2.0
MEDIUM 6.1 The Relevant – Related, Featured, Latest, and Popular Posts by BestWebSoft plugin for WordPress is vulnerable to Refle… wordfence
ea0eeb86-73af-4f7c-9f2f-dc9930948c0c
< 1.3
MEDIUM 6.1 The ALD Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
ea0d5859-7304-4d65-9ba9-679d0fc3c3fd
< 1.7
MEDIUM 6.1 The Easy Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'easy_table_plugin_option' paramete… wordfence
ea0540d1-3c02-43e7-852c-bf9a6c025fc4
< 5.9.5.8
MEDIUM 6.1 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scr… wordfence
e9f9f72f-01f4-47db-8efd-f25f0276896f
< 1.29.1
MEDIUM 6.1 The Name Directory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
e9f090bb-8e85-4fc3-a904-0a7ff85db8f1
< 1.2
MEDIUM 6.1 The SMTP Mail plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versi… wordfence
e9d7eed2-deba-49bc-99be-96fdc1331f7c MEDIUM 6.1 The Mergado Pack plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
e9cf6b7f-d2b0-47f9-beec-8773f260c088 MEDIUM 6.1 The LockerPress – WordPress Security Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve… wordfence
e9ce5c8e-35e2-4148-a6a8-69cd6cabb494 MEDIUM 6.1 The Form To JSON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
e9c68edb-99ad-4103-aff5-48abcf5c4392
< 6.8
MEDIUM 6.1 The Vayvo theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 6.8 due to insufficient … wordfence
← Prev 785 786 787 788 789 790 791 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top