ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 791 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e76e4c4c-3f84-46b0-b305-2513714a8525
< 1.2
MEDIUM 6.1 The Proofreading plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
e75cc91a-9117-4d18-ba70-d8cbae42cd08
< 2.1.1
MEDIUM 6.1 The Post Type Builder (PTB) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
e75b3cc3-5bd6-4af9-94bf-2c3b6270e1c5
< 2.1.8
MEDIUM 6.1 The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape so… wordfence
e753b8cd-8409-4bcf-9bee-0eb70179f3a3
< 3.0.5
MEDIUM 6.1 The Avante theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 3.0.5 due to insufficie… wordfence
e72b2656-48d6-4d69-b4d0-e7efe0950554 MEDIUM 6.1 The ChatGPT Open AI Images & Content for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
e7222029-0dac-4c96-9bbd-4e040b65fb99
< 7.2.5
MEDIUM 6.1 The Booster Plus for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
e72155ce-d38d-45d1-906c-305bb9b34b45 MEDIUM 6.1 The NAVER Analytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
e70db623-722d-4255-8eee-b022e8cfa3be MEDIUM 6.1 The Google News Editors Picks Feed Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
e70a1197-b5b1-4f30-a253-89eb198c670e
< 1.1.6
MEDIUM 6.1 The CleverNode Related Content plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
e6facfb9-16d8-42dc-9c7d-fd1dd1342f81
< 4.7.9
MEDIUM 6.1 The Jobmonster theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.7… wordfence
e6f549c8-673b-4032-9b56-5a2e2239eff3
< 13.2.2
MEDIUM 6.1 The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back i… wordfence
e6f1907e-9584-4ff7-8cf5-b285b7df9ec4 MEDIUM 6.1 The simpleSAMLphp Authentication WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_S… wordfence
e6ee592b-df73-46cb-97cd-56f1e2a0d09a MEDIUM 6.1 The Simple User Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
e6c4e102-7a09-4a01-8fa2-40f5f41d45ab
< 1.7.5
MEDIUM 6.1 The ACF Photo Gallery Field WordPress plugin before 1.7.5 does not sanitise and escape the post parameter in the include… wordfence
e6b289c2-0e04-43b1-baf1-6a594cc47ea0
< 0.6.1
MEDIUM 6.1 The AntiSpam for Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
e6aa8089-1c29-41ef-b2c0-06841751f7a5 MEDIUM 6.1 The CSV Sumotto plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` vari… wordfence
e69122ed-8f18-4f2d-ba77-7538c7b6de6d
< 2.0.2
MEDIUM 6.1 wordfence
e68bbee2-1c1a-4751-988e-dde423f8aab3
< 2.10.8
MEDIUM 6.1 The PowerPack Pro for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions prior to 2.… wordfence
e689270f-0340-42dc-8693-65f152e52fb1 MEDIUM 6.1 The Language Field plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
e6809f7f-4495-4185-b439-820010afc305 MEDIUM 6.1 The WooCommerce JazzCash Gateway Plugin plugin for WordPress is vulnerable to Cross-Site Scripting via an unknown parame… wordfence
e67dfe0f-ac1c-4a78-bfc9-0cfd6c3040d4
< 1.0.20
MEDIUM 6.1 The Responsive Filterable Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_… wordfence
e67b6467-b96b-431c-9a0d-91919ab1c138
< 5.3.2
MEDIUM 6.1 The WooCommerce License Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
e67227d2-3fee-4da5-ac8c-00770beab4ce MEDIUM 6.1 The DX Sales CRM plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
e66d0c9c-39a2-4f09-b87f-630f1a8054ea
< 6.1
MEDIUM 6.1 The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which co… wordfence
e66bd1e1-a299-42ea-a97a-7d9acaa3519e MEDIUM 6.1 The OmniLeads Scripts and Tags Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
← Prev 788 789 790 791 792 793 794 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top