🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 789 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e9bf506f-17b1-4ec3-87ce-1ed78db6fb0b
< 51.02
MEDIUM 6.1 The Broadcast plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'do_check' parameter in all v… wordfence
e9b918e1-9bf7-4f90-9e77-829bc8012cbb
< 1.2.8
MEDIUM 6.1 The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date… wordfence
e99d5841-9fd0-451f-b6fe-bac0851f4aaf MEDIUM 6.1 The CodeBard Help Desk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
e98b1bc7-8dcb-4fcf-9238-598ce53e443e
< 1.01
MEDIUM 6.1 The dwnldr plugin before 1.01 for WordPress has XSS via the User-Agent HTTP header. wordfence
e98ab8ba-d165-4813-abdb-c7d47a93d30f MEDIUM 6.1 The Hello Followers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
e9885db9-b1eb-4cc6-a7ea-af2c34b1d065
< 2.0.3.1
MEDIUM 6.1 A Cross-site Scripting (XSS) vulnerability exists in the All in One SEO Pack plugin before 2.0.3.1 for WordPress via the… wordfence
e9688229-90e8-4530-9039-5ba8c8bcf93e
< 1.0.8
MEDIUM 6.1 The B2i Investor Tools plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
e9489254-dbdc-4754-86d0-d28756b269a9
< 5.1.1
MEDIUM 6.1 The ProfileGrid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versi… wordfence
e947abb8-be40-4090-80a6-5255692ef693
< 3.6.3
MEDIUM 6.1 The BuddyStream plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'link' parameter in all ver… wordfence
e938c126-e24d-4299-891a-438e7ba513e7 MEDIUM 6.1 The MMX – Make Me Christmas plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
e928ed4b-5f27-4e0d-af0b-30256b851454 MEDIUM 6.1 The Dashing Memberships plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
e9178920-d865-45d3-bfdf-b8ad207d4546
< 2015.0426
MEDIUM 6.1 The FeedWordPress plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 2… wordfence
e9171908-5b6e-44f3-ab93-899932be527f
< 1.6.9.2
MEDIUM 6.1 The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName. wordfence
e915f1b5-50cd-4c2a-ad01-feab799d071f
< 10.46
MEDIUM 6.1 The Subscribe2 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 10… wordfence
e8fa1f97-72f6-4e84-bee4-0d3f7e16eb96 MEDIUM 6.1 The Uploadify Integration plugin for WordPress is vulnerable to Multiple Reflected Cross-Site Scripting via several para… wordfence
e8f6d6f8-42c6-4613-88bf-c00fcc6a9ffe MEDIUM 6.1 The Podčlánková inzerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
e8f6cabb-ecf5-44f1-bc39-20d9dc989600 MEDIUM 6.1 The Custom DataBase Tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
e8f20aae-37e2-44f6-ac2d-692a87bf5728
< 3.0
MEDIUM 6.1 The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST. wordfence
e8db52ce-fbc3-4fe1-b9b4-cb2ce7d88a67
< 0.9.3
MEDIUM 6.1 The Maspik – Spam Blacklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the efas_add_to_log … wordfence
e8cbd8ee-1bd5-43ea-8e67-5ad893258512 MEDIUM 6.1 The Advance WP Query Search Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up t… wordfence
e8c74105-3f0c-4322-96f3-e6bf4760cc2f MEDIUM 6.1 The Blaze Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions d… wordfence
e8bc24df-4d95-44b7-a58c-00a1b24f91e9
< 1.23
MEDIUM 6.1 The LH Add Media From Url plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
e8a864ff-2c0e-40c3-8c4e-dc034d8838b9
< 3.3.8
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Relevanssi plugin before 3.3.8 for WordPress allows remote attackers to … wordfence
e88bb3a8-de24-46fb-a3e4-9ca3fdd4cca7
< 1.0.23
MEDIUM 6.1 The video carousel slider with lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the sea… wordfence
e88afde4-6920-4086-940e-34b4a4ee30c5 MEDIUM 6.1 The WordPress InviteBox Plugin for viral Refer-a-Friend Promotions WordPress plugin is vulnerable to Reflected Cross-Sit… wordfence
← Prev 786 787 788 789 790 791 792 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top