🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 798 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e046c7d0-5660-4a16-ab0a-848448b033bd
< 2.7.0
MEDIUM 6.1 The Easy Form by AYS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
e031dbef-1f7a-4c17-803a-fd467978d7f3
< 4.7
MEDIUM 6.1 The turboSMTP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.6… wordfence
e02cf6d3-3c50-4da5-b28c-7bda30deca3e MEDIUM 6.1 The WP Scrippets WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"… wordfence
e01532bb-3011-4efe-b072-d0df5708f8e9
< 2.9.52
MEDIUM 6.1 The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameter… wordfence
e012d7a0-46f9-4f3b-a178-2d06655fd441
< 2.03
MEDIUM 6.1 The plugin External url as post Featured Image plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in v… wordfence
e00ba29c-acdc-42ba-a6f7-cd064aec662d MEDIUM 6.1 The Perfect Survey WordPress plugin before 1.5.2 does not sanitise and escape multiple parameters (id and filters[sessio… wordfence
e0073811-b4c9-40fd-a839-a27681a69034
< 6.7.2411.00
MEDIUM 6.1 The CarDealerPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
dfd638bb-ae0b-403d-8d34-c4b62a749d7f
< 1.3.6.7
MEDIUM 6.1 The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab p… wordfence
dfafdc46-e747-42b4-963b-7b966b1f67a4
< 6.8.2
MEDIUM 6.1 The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile … wordfence
dfa2dc9c-08c2-4e24-8432-84938e52ece6 MEDIUM 6.1 The Advanced Control Manager for WordPress by ItalyStrap plugin for WordPress is vulnerable to Reflected Cross-Site Scri… wordfence
df9ca3c2-8bc8-4e15-8dc9-f2dd6f80d968 MEDIUM 6.1 The WP Cookies Alert plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
df9ad765-dc7b-4da6-951e-045274caeaae MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in blogroll.php in the cordobo-green-park theme for WordPress allows remote att… wordfence
df8047cf-bf6d-42f5-9a77-1fd3472aa2ce MEDIUM 6.1 The Oppso Unit Converter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
df5c31fc-48ae-4152-b1e7-f280b1d93ca6 MEDIUM 6.1 The Loan Calculator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
df54a888-fe7a-43ef-a77f-fb6e3401defe MEDIUM 6.1 The Embed Swagger WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping/sanitiza… wordfence
df4ad83f-280e-46fa-ad47-3822fa67b10d
< 5.5.7.1
MEDIUM 6.1 The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS via the dbem_event_reapproved_email_body parameter. wordfence
df498694-43fd-4c46-aafa-5448497ddbf0 MEDIUM 6.1 The Responsivity plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
df3b5124-1151-4402-b30f-038470c7a951
< 1.5.9
MEDIUM 6.1 The TS Poll – Best Poll Plugin for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via … wordfence
df2ebfb9-f973-44f2-8398-cbaafb13e6b0 MEDIUM 6.1 The Rocket Media Library Mime Type plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
df2e744f-e1d6-4380-8e24-e98e9df4dd2f
< 1.4.4
MEDIUM 6.1 The FunnelCockpit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error’ parameter in … wordfence
df20aa75-c6d3-48a6-9b19-7547bf12fb82 MEDIUM 6.1 The WP Athletics WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting back in an ad… wordfence
df080dba-0f50-4ff4-bf4d-01f71f92f960 MEDIUM 6.1 The CheckBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.05… wordfence
deffffaa-a593-4500-8809-4eb16f6ad189 MEDIUM 6.1 The Ultimate Learning Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
def0da23-248b-40e2-9d70-8dd1ecbe3d45
< 4.2.1
MEDIUM 6.1 The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to missing sanitization and esc… wordfence
dee03f28-2cca-4b07-b604-1f5a278af7d1 MEDIUM 6.1 The Envato Affiliater plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
← Prev 795 796 797 798 799 800 801 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top