πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 792 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e662761d-1dc8-4998-83b5-316ce683b5b6
< 5.9.8
MEDIUM 6.1 The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an a… wordfence
e65cf73b-349b-4982-b6ec-a2c94d327d0a MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Marekkis Watermark plugin 0.9.4 for WordPress allows remote attackers to… wordfence
e6481a6e-5875-44d8-9b24-594fb73e8942 MEDIUM 6.1 The Covert VideoPress Theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerab… wordfence
e647fcde-e36a-4432-abec-73e414991e96
< 3.0.15
MEDIUM 6.1 The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (X… wordfence
e632b842-b3d2-461f-aaed-e413d98964a5 MEDIUM 6.1 The Support Helpdesk Ticket System Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions… wordfence
e6270944-31c0-4d6d-a23f-87fce37ff8b0
< 3.1.10
MEDIUM 6.1 The SyntaxHighlighter Evolved plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includin… wordfence
e621c82c-ab35-4188-a592-03c09b70f0ae
< 1.7.2
MEDIUM 6.1 The Web Directory Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'hash' parameter in … wordfence
e61110fc-cc2d-4207-97b6-b21459334216
< 1.9.1
MEDIUM 6.1 The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the… wordfence
e60de5d9-34f8-4068-b656-11b2b6cb36d4
< 1.5.1
MEDIUM 6.1 The Keyring plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerable OAuth … wordfence
e6003a2a-dda5-4db4-8a0c-0d26d79529f2
< 2.3.1
MEDIUM 6.1 The core plugin for kitestudio themes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the kite_… wordfence
e5ed3ec3-1c05-4fff-a453-11536cfbb366 MEDIUM 6.1 The Pin Locations on Map plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
e5df79e6-649e-4213-b2ff-bc994b372224
< 3.3.5.9
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attac… wordfence
e5db103a-a823-47ac-a1f4-c297619cf1a4
< 2.0.0
MEDIUM 6.1 The Z-URL Preview plugin 1.6.1 for WordPress has XSS via the class.zlinkpreview.php url parameter. wordfence
e5d82cd5-42cc-412b-8026-53736680407d MEDIUM 6.1 The Ultimate Blogroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
e5d67eb3-c399-437e-a504-2ccdda7c7882
< 1.8.0
MEDIUM 6.1 The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter befo… wordfence
e5c89df2-69be-4b58-ad3c-ba0191e3d701 MEDIUM 6.1 The GNUCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
e5b98a2c-faed-4e2b-8b94-31e2be95ad40
< 1.3.5
MEDIUM 6.1 The WPZOOM Addons for Elementor – Starter Templates & Widgets plugin for WordPress is vulnerable to Reflected Cross-Si… wordfence
e5b00388-48b8-4e82-ab52-1cd3d02177b7
< 0.6
MEDIUM 6.1 The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all v… wordfence
e5a7b18b-3a92-4065-9c0d-9979eeacff93 MEDIUM 6.1 The Awesome Studio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
e5a53e42-ad71-4c13-b18b-9958656bbee4
< 3.8.1
MEDIUM 6.1 The BSK Forms Blacklist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'target' parameter … wordfence
e599393b-f009-4a3f-a89e-6219ecf33efc
< 2.1.1
MEDIUM 6.1 The Donate by BestWebSoft – Donations Acception Extention for WordPress plugin for WordPress is vulnerable to Reflecte… wordfence
e5986c72-ae6d-4cd2-929d-fe2ff6462b4f
< 1.3
MEDIUM 6.1 The Syndication Links plugin for WordPress is vulnerable to DOM-based Cross-Site Scripting via the genericons/example.ht… wordfence
e5863e9b-3f98-41ea-97ed-26563493cffd
< 1.12.4
MEDIUM 6.1 The WP ERP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.12.3… wordfence
e582f3e8-f8c5-4168-bc5b-856dccab622b
< 1.7.4
MEDIUM 6.1 The tagDiv Opt-In Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
e5726c70-c2c7-45b9-bd03-38cf1320646a MEDIUM 6.1 The Brilliance theme for WordPress is vulnerable to Relected Cross-Site Scripting in versions up to, and including, 1.3.… wordfence
← Prev 789 790 791 792 793 794 795 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top