🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 797 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e11993c1-48fa-4e37-850d-d02e3e20d56f
< 2.41
MEDIUM 6.1 The Pure Chat – Live Chat & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘purecha… wordfence
e1114a46-fd1c-4707-bd42-524c0c6fd4c8
< 3.3.8
MEDIUM 6.1 The Oshine Modules plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
e10fc7e4-11ec-409b-9f16-b38adceaf622
< 2.0.9
MEDIUM 6.1 The PropertyHive plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
e10dd0e6-1567-437b-ace7-fae013d66514
< 6.5.5
MEDIUM 6.1 The Custom Dashboard & Login Page – AGCA plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … wordfence
e0f2fe23-c77c-4e24-a1e4-0aa3697370e6
< 1.1.3
MEDIUM 6.1 The Easy Digital Downloads (EDD) Cross-sell Upsell extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x b… wordfence
e0f19403-af02-4a29-b4f3-778da4c2df17
< 19.6.25
MEDIUM 6.1 The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
e0e70739-88c2-498e-b96c-1f27b8641cb8
< 3.8.3
MEDIUM 6.1 The Sliced Invoices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in ver… wordfence
e0e177f3-fb24-4dd5-80d5-19b113d5f527
< 4.1.7
MEDIUM 6.1 The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, … wordfence
e0d6b3ae-0449-405a-8942-c8e01ce00b56 MEDIUM 6.1 The Super Logos Showcase plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
e0d5b1a5-0078-402b-b834-8091bfc02dd5
< 4.4.1
MEDIUM 6.1 The EventON Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all ver… wordfence
e09e48db-f74a-4663-a724-24938a6c277c
< 1.2.3
MEDIUM 6.1 Multiple themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'id' parameter found in the '[dif… wordfence
e09c2916-6e2c-4db3-901a-b5715d635824
< 2.7.0
MEDIUM 6.1 The PeproDev WooCommerce Receipt Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to th… wordfence
e0976e3c-dcc2-41aa-a734-84afa50310ed MEDIUM 6.1 The MJ Update History plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
e0930c96-79e7-40a8-beee-17daf834b9d1 MEDIUM 6.1 The Content Planner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
e08c0e74-4ce0-4278-8f58-909f7c24f346 MEDIUM 6.1 The Restaurant Reservations Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up t… wordfence
e0882303-ca16-45ae-8aee-bbce7a8c17f1 MEDIUM 6.1 The Web2application plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
e0861584-6850-40c6-92d4-b4efb1ea103f
< 3.0.1
MEDIUM 6.1 The Contact Form 7 Math Captcha plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tagname' p… wordfence
e077570f-39d3-414f-8138-b1dd2077e476 MEDIUM 6.1 The WP Filter Post Category plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
e076e054-6a0b-4c08-b0cc-bd3a5b0751e5
< 3.2.25
MEDIUM 6.1 The Front End Users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
e0755c8f-89c4-45a5-95a4-fcfe985f037f
< 1.4.3
MEDIUM 6.1 The A Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1… wordfence
e06ceba5-9c50-442e-9cba-da64a38de00f
< 1.8.8
MEDIUM 6.1 The All in One Support Button + Callback Request plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a… wordfence
e05a0a28-cc3b-44ed-b815-5f6e5d75007e MEDIUM 6.1 The Event Countdown Timer Plugin by TechMix plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all … wordfence
e057a35b-8162-4636-9fd9-419378df1ca1
< 1.3.5
MEDIUM 6.1 The Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search field in versions … wordfence
e04f7702-87d2-45d0-9402-71cb6144a275 MEDIUM 6.1 The Ajax Content Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
e04e2f24-ca52-4f7c-961b-f35b9ff90536
< 4.2.5
MEDIUM 6.1 The social-locker plugin before 4.2.5 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=opan… wordfence
← Prev 794 795 796 797 798 799 800 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top