🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 793 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e56ebe2a-8a7e-454b-a1cd-7103112087e0 MEDIUM 6.1 Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.17 (and possibly more) could allow remote attackers to in… wordfence
e54c1a85-13f6-48c0-9db8-860b4b1f3e45 MEDIUM 6.1 The WP Front-end login and register plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the email a… wordfence
e54b0294-6829-493f-b7d3-6349000c249c MEDIUM 6.1 The Tax Rate Upload plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
e5438f82-2428-44ba-a7c8-e34d80804063
< 1.0.27
MEDIUM 6.1 The PayGreen Payment Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message_id' p… wordfence
e532a2b4-0fb4-4256-89a9-435b55d9de91
< 3.2.16
MEDIUM 6.1 The WordPress Membership, User Registration, Login Form, User Profile & Restrict Content Plugin – ProfilePress plugin … wordfence
e52914cc-da0c-4b79-b378-4ef63e7974bb
< 3.0.6
MEDIUM 6.1 The Real Estate 7 Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters (ct_sqft_fr… wordfence
e51a0db0-0ee0-463b-8d82-81a991ef9222
< 2.3.6
MEDIUM 6.1 The animate-it plugin before 2.3.6 for WordPress has XSS. wordfence
e510fc07-c969-48f4-ac5a-7dc91f9e2cd5 MEDIUM 6.1 The Wp-Scribd-List plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
e50a998e-b6f2-443a-83a9-299def2420c5
< 3.1.0
MEDIUM 6.1 Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web … wordfence
e4fd4e36-d9f1-4fb4-8c65-4eebc2097666
< 2.0.0
MEDIUM 6.1 The MSRP (RRP) Pricing for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … wordfence
e4fa7eee-21c9-479e-bbc5-b20f41f94c25 MEDIUM 6.1 The Gameplan theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.1… wordfence
e4f24b32-58a0-4b10-b8ff-65e574966b6e
< 1.4.2
MEDIUM 6.1 The Waymark plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all … wordfence
e4e16526-89a5-4d49-ab9d-dcc7ad3bc8d0
< 1.2.6.3
MEDIUM 6.1 The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues. wordfence
e4d61b69-f3de-4408-98f7-18027a47d168 MEDIUM 6.1 The xili-dictionary plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
e4c7ca5c-38aa-4413-83eb-29185cca2a74 MEDIUM 6.1 The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting … wordfence
e4c27225-f9db-4ae5-bb1f-ce8648c216eb
< 1.3.15
MEDIUM 6.1 The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid p… wordfence
e4baead0-7126-457a-abe0-0c9bf239ea15
< 1.2.1
MEDIUM 6.1 The Related Videos for JW Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
e4ba2243-8a4f-4ecb-8f77-6f4fd24865e3
< 0.9.5
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin < 0.9.5 for WordPress allows remote attackers to … wordfence
e4b94952-229c-4336-a985-d2f47c89f7de MEDIUM 6.1 The InstaSqueeze Sexy Squeeze Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' pa… wordfence
e4b7fa61-f760-48f4-b30e-9c63f2d388f9 MEDIUM 6.1 The Simple Page Specific Sidebars plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
e4b7f31c-084e-489c-a902-c16e62b99e45
< 1.5.9
MEDIUM 6.1 The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.9 does not escape the current URL before putting i… wordfence
e4a853e0-0ebc-4ed5-b6ff-ce3973fb3ee1
< 4.2.3
MEDIUM 6.1 The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via popups in versions up to 4.2.3 d… wordfence
e4a5dc4f-3eb6-410e-af3d-e3b0639319f3
< 3.8.9
MEDIUM 6.1 The PayU India plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘type’ parameter in vers… wordfence
e4a32267-6d99-4882-8601-8c4d36575e0f
< 1.4.3
MEDIUM 6.1 Multiple cross-site request forgery (CSRF) vulnerabilities in the Sharebar plugin 1.4.2 for WordPress allow remote attac… wordfence
e4a2d6ee-ee1b-44a1-ad74-61837d9ef4b2
< 11.1.12
MEDIUM 6.1 The SEO Plugin by Squirrly SEO WordPress plugin before 11.1.12 does not escape the type parameter before outputting it b… wordfence
← Prev 790 791 792 793 794 795 796 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top