🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 796 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e249e50b-44fb-4e68-9efa-701f4ecdcdcf
< 1.1
MEDIUM 6.1 Reflected XSS in wordpress plugin tidio-form v1.0 wordfence
e247c919-6210-4769-9022-d7f7a0178f14
< 5.5
MEDIUM 6.1 The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post. wordfence
e23bdcf9-8068-40c5-b27e-4562040068ca MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in admin/editFacility.php in the wp-easybooking plugin 1.0.3 and earlier for Wo… wordfence
e236a01d-5561-45f6-927c-9e38f6d82eff MEDIUM 6.1 The Invico - WordPress Consulting Business Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in … wordfence
e2283bd6-7d69-40b9-a1f3-56b9c71c8574
< 3.5.5
MEDIUM 6.1 WooCommerce before 3.5.5 allows XSS via a Photoswipe caption. wordfence
e218d5e8-cd48-46da-b63b-e33483a8798e
< 4.1.0
MEDIUM 6.1 The Listdom – Business Directory and Classified Ads Listings WordPress Plugin plugin for WordPress is vulnerable to Op… wordfence
e205d8f3-3855-4c59-9537-36ae24b1e840
< 3.15
MEDIUM 6.1 The CSV to html plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3… wordfence
e1fad1e1-5fb8-4423-80d3-512f5ec7dd59 MEDIUM 6.1 The Custom Smilies plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
e1eeabdb-f1c0-49c5-9234-8ff4eaa38087
< 2.0.18
MEDIUM 6.1 The WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.0.17 via … wordfence
e1e9bf39-b0aa-457c-96ed-87d3d96a1eec MEDIUM 6.1 The electrician theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
e1baa3f0-28ec-409f-a9a5-c35545ab439a
< 2.0.8
MEDIUM 6.1 The Goodlayers Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘font-family’ param… wordfence
e1a3ea4c-163f-406c-a819-92d3157fd93f
< 4.6.4
MEDIUM 6.1 The Albo Pretorio Online plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
e19f69ee-180a-44b7-8d41-3630c6932dda MEDIUM 6.1 The custom-post-edit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
e18ae7a9-7761-432f-a983-16ff1131c1e8 MEDIUM 6.1 The Advanced Category Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _form.php file … wordfence
e177c03c-20bd-4135-b72f-fbceab88a117 MEDIUM 6.1 The Anonymize Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
e16d8d28-e1e5-46ab-a64c-1da07747559e MEDIUM 6.1 The Twittee Text Tweet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `tweetTooltip` and `… wordfence
e167eedc-0828-4707-85b9-a78f9aeff27e
< 1.6.21
MEDIUM 6.1 The BA Book Everything plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
e15b81f7-4d3b-4505-b345-1019fed0fef1
< 1.4.2
MEDIUM 6.1 The WooSidebars plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in versions up to, and in… wordfence
e157826d-77d5-4b2b-9925-691defa54e08 MEDIUM 6.1 The Multimedia Playlist Slider Addon for WPBakery Page Builder plugin for WordPress is vulnerable to Reflected Cross-Sit… wordfence
e15441f3-3ffe-4466-9119-e5354fd1c1c4
< 5.1.6
MEDIUM 6.1 The User Registration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
e15082f4-2b5e-4538-bcac-c9e27b129e03 MEDIUM 6.1 The Quote me plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … wordfence
e13c6d97-873a-4067-846d-92e54514645d
< 1.2.7
MEDIUM 6.1 The Nioland theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in all version… wordfence
e136ab52-a193-430b-b2b2-d7640d009c99
< 7.4.5
MEDIUM 6.1 The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it … wordfence
e12e2ba1-fc4f-4ad0-80da-3504ef1e13d3 MEDIUM 6.1 The Simple AL Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']`… wordfence
e12dcad4-747b-40ba-96f3-746fa2abef74 MEDIUM 6.1 The Contact Form 7 – CCAvenue Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … wordfence
← Prev 793 794 795 796 797 798 799 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top