πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 795 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e3cc99df-b709-40e7-a911-ea19f5af2c82
< 1.3.0
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.3.0 for WordPre… wordfence
e3c10baf-f68a-454a-af66-e1526de83253
< 1.7.06
MEDIUM 6.1 The WorkScout-Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 1.7.06 due to … wordfence
e3a21a39-ed2a-4ca2-b8e2-c489c007e108 MEDIUM 6.1 The Page/Post Specific Social Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers… wordfence
e39044c6-8b72-478d-a762-418b2c58429a
< 1.1.46
MEDIUM 6.1 The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1. wordfence
e3885ca9-6771-40c9-9c19-fbb8696cfb4e
< 0.5.8.5
MEDIUM 6.1 The Off-Canvas Sidebars & Menus (Slidebars) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in vers… wordfence
e36eed5b-f76d-451e-a0f8-fd4b91bcf9f1
< 5.8010
MEDIUM 6.1 The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5… wordfence
e36b5889-19a3-4ae7-93bd-2ab404fce085
< 1.1.2
MEDIUM 6.1 The WP Sessions Time Monitoring Full Automatic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in v… wordfence
e356ff89-220f-4597-9327-9ce1a0226056 MEDIUM 6.1 The Site Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
e340f400-1d20-4fa1-9cc7-8c0f49075bc0
< 2.0.10
MEDIUM 6.1 The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has … wordfence
e31aba91-d475-4ea5-a0dc-ff8426866407 MEDIUM 6.1 The WP2APP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.… wordfence
e316c636-2dd7-4d50-8c99-36f08ecf03ad
< 2.3.67
MEDIUM 6.1 The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to DOM-Based R… wordfence
e2f94d61-a3ec-4e25-bbd0-651b553b9c7c
< 3.8.2
MEDIUM 6.1 The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in … wordfence
e2f57c50-f6d1-4583-a75e-17c543ed7fa6
< 1.4
MEDIUM 6.1 The Booking System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜eid’ parameter in v… wordfence
e2d564a5-52c7-48e0-abb6-9006ecc35806 MEDIUM 6.1 The WP-Clap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1… wordfence
e2b9d1dc-0f8d-4f61-b870-3266b241e4e1
< 1.5.1
MEDIUM 6.1 The Responsive Modal Builder for High Conversion – Easy Popups plugin for WordPress is vulnerable to Reflected Cross-S… wordfence
e298663b-746c-40fc-a2ca-cb35d472baab
< 4.6.20
MEDIUM 6.1 The Amazon Auto Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' and 'name' val… wordfence
e29352df-6fd6-4560-aa46-848de0ef8653 MEDIUM 6.1 The SEOReseller Partner Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
e292e704-4b98-4e95-ac25-29cedcf005c7
< 1.5.0.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in index.php in the Blue Memories theme 1.5 for WordPress allows remote attacke… wordfence
e287fa29-07a7-4fbd-9bf2-c3eee8514a20 MEDIUM 6.1 The WP Bulletin Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
e2795202-64e6-488b-a0e1-da2923f6f791 MEDIUM 6.1 The Marketing Twitter Bot plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
e26a438d-7e2d-47de-81f2-39731ce51bd6
< 1.1.0
MEDIUM 6.1 The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did n… wordfence
e268bf8d-066c-410c-85ef-135591a2922b
< 1.8.21.0
MEDIUM 6.1 The WP Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
e25ef117-72c4-4696-9248-5caa937b47e9 MEDIUM 6.1 The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[f… wordfence
e2579e45-0cdc-42d8-b6c1-f43b97a0781f MEDIUM 6.1 The Finale Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2… wordfence
e252f833-3b0c-44df-969d-aff9314133b7 MEDIUM 6.1 The So Audible Cloud Music Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
← Prev 792 793 794 795 796 797 798 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top