πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 794 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e4a00ad0-5761-4fb7-a4e6-cb213cf32cb2
< 1.3.7
MEDIUM 6.1 The FormFacade – WordPress plugin for Google Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
e4953824-02e8-46cb-a4a8-4fe3746d900c
< 1.9.18
MEDIUM 6.1 The Testimonials Showcase plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
e4905c33-3e6b-4331-aeea-d2083f4788bf MEDIUM 6.1 The More Mime Type Filters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
e4889359-6311-4d21-ad67-e2a5bcbadd22 MEDIUM 6.1 The CWD 3D Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
e486b0b5-5ee6-4ea2-bf0d-45a4302ce20f MEDIUM 6.1 The Copyright Safeguard Footer Notice plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
e4773d95-17ce-4c16-a1ba-953687ecb0b0
< 1.4.2
MEDIUM 6.1 The HTML Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
e4767df8-eafd-47cf-8c70-431db7a3a3f8
< 3.4.3
MEDIUM 6.1 The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.4… wordfence
e475e420-7ab7-4f29-aacf-d758af90694c MEDIUM 6.1 The List Urls plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.2… wordfence
e4731811-23d7-4a8e-8db3-794077720545 MEDIUM 6.1 TheDaisho Theme plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.2 due to … wordfence
e4704495-8342-4846-9242-f1eab4de25d6
< 2.0.47
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in bad-behavior-wordpress-admin.php in the Bad Behavior plugin befor… wordfence
e46e8a7e-4032-4357-9553-d03bdf168383
< 3.5.2
MEDIUM 6.1 The MakeCommerce for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… wordfence
e46a2031-e304-43fb-85bf-ec9abf0b2f90
< 2.1.8
MEDIUM 6.1 The Doofinder for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting the 'tab' parameter i… wordfence
e46732ac-1aa4-434d-8c49-7ed065bc907b
< 1.1
MEDIUM 6.1 The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an… wordfence
e45dd9f6-9cc6-42d0-b03f-65fda85425f2 MEDIUM 6.1 The Load More Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
e456b8c8-ba4a-4199-b006-c6be381b6ef8
< 1.8.14
MEDIUM 6.1 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '… wordfence
e452886b-d49a-4363-9d9b-f922bcd902ca
< 3.0.7
MEDIUM 6.1 The Etsy Shop plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI'] param… wordfence
e43713c7-32bd-4b82-a4da-6c02d91f3d3e
< 4.3
MEDIUM 6.1 The APIExperts Square for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions u… wordfence
e43482e1-7e11-49a6-bb44-0db421b51ed1 MEDIUM 6.1 The MobileChief – Mobile Site Builder for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
e422aa58-a335-4734-bbcd-d400bd44bc89 MEDIUM 6.1 The WP Hallo Welt plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
e409a4af-9998-4b77-8f6b-50ae1b70da2d
< 3.0.8
MEDIUM 6.1 The Sitemap by BestWebSoft – WordPress XML Site Map Page Generator Plugin plugin for WordPress is vulnerable to Reflec… wordfence
e40129a9-731a-4443-8906-8fe697c04f59 MEDIUM 6.1 The Password Protect Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
e3f59671-0db2-4acf-8e97-a0ead518bebd MEDIUM 6.1 The Archivist – Custom Archive Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versi… wordfence
e3ec1716-8e44-4cd6-b830-800716e3624b MEDIUM 6.1 The Simple Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
e3e1833e-31de-418b-bbd3-d41daa3ac9d5
< 1.0.2
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the Newsletter Manager plugin before 1.0.2 for WordPress allow re… wordfence
e3d040ca-c1cd-44e9-a916-37572fbade74
< 1.4
MEDIUM 6.1 The Custom Field For WP Job Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up … wordfence
← Prev 791 792 793 794 795 796 797 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top