🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 815 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cf1e4b20-e7e5-4a3a-9895-02d51499d54e MEDIUM 6.1 The Lucas String Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_quer… wordfence
cf1cc19a-2ca2-4322-9f37-3f7e24ea38c6
< 1.0.8
MEDIUM 6.1 The Transposh WordPress Translation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' par… wordfence
cf19c42c-5711-42e0-b325-093001d7ee54 MEDIUM 6.1 The Libro de Reclamaciones plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
cf0c7e3e-b6f3-4c99-bf8a-13b890c870bb MEDIUM 6.1 The Secret Meta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
cf0c34d3-5c7d-43a5-9430-2ebdc155123f
< 3.18
MEDIUM 6.1 The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the order parameter… wordfence
cf0798cd-bf1a-4c1c-82c5-e417b9983c77 MEDIUM 6.1 The WP Realty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘listing_id’ parameter in… wordfence
cf02db2c-5fd2-4f21-a95c-e7645e22ecc6
< 2.2
MEDIUM 6.1 The WP Advanced Importer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘alertmsg’ par… wordfence
cf00d5a9-bf7f-404c-b91f-1d7cf14d883b
< 1.2.0
MEDIUM 6.1 The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page… wordfence
cefdf1c5-eab4-4f06-aa5c-24cdef36e5f9 MEDIUM 6.1 The Misiek Paypal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
ceea74e0-afb2-4b5c-a538-48aace4d9619
< 6.10.11
MEDIUM 6.1 The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msearch' parameter … wordfence
cedf0d4c-ee4c-4400-883c-46abe05795c0 MEDIUM 6.1 The Email Keep plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'type' parameter in all vers… wordfence
ceaf64d6-9872-4572-807e-7fce76edee57
< 1.6
MEDIUM 6.1 The Fish and Ships – Most flexible shipping table rate. A WooCommerce shipping rate plugin for WordPress is vulnerable… wordfence
ceaf5f81-1adf-4512-b610-d1d183876762
< 4.2
MEDIUM 6.1 The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter befor… wordfence
cea8295b-b4be-4a95-9137-ad2033a5169d
< 1.4.2
MEDIUM 6.1 The Pulsating Chat Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
ce9ec867-a23a-4081-b791-c6dba6985294
< 5.2.0
MEDIUM 6.1 The YITH WooCommerce Ajax Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… wordfence
ce9e9298-7ff3-4ecc-9665-cc4a3b76059c
< 2.4
MEDIUM 6.1 The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) plugin for WordPress is vulnerable to Cross-Site Scripti… wordfence
ce96dab2-70ab-4925-8323-daf65d61c81a
< 0.7.9.4
MEDIUM 6.1 The Connections Business Directory for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown paramete… wordfence
ce96ab3a-a8a4-44a3-80ce-3a3ec419db47
< 2.4.15
MEDIUM 6.1 The easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg plugin for … wordfence
ce8f8883-f069-4896-8c5f-93600d2c2e6d
< 4.1
MEDIUM 6.1 The Stylish Google Sheet Reader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lim' param… wordfence
ce8526f0-9dfb-4020-aa58-d2ff5bd652bf
< 4.3.0
MEDIUM 6.1 The WP Helper Premium plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
ce6c2f36-9eed-482f-9201-8d26e8c5c369
< 2.244
MEDIUM 6.1 The Ashe theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without app… wordfence
ce5efd37-131f-4b75-b682-023a07070ca0 MEDIUM 6.1 The WP Academic People List WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category_name param… wordfence
ce4fd12c-824c-44b9-a5be-d2f1abf79acc
< 1.0.6
MEDIUM 6.1 The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up … wordfence
ce4e415b-a0d9-47fd-a111-76b81bcac12f MEDIUM 6.1 The TheNa theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.5 du… wordfence
ce336caf-fc71-4b16-8824-d3e34a1eb69e MEDIUM 6.1 The Spare - Ultimate MultiPurpose LESS Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all … wordfence
← Prev 812 813 814 815 816 817 818 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top