πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 816 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ce2a438c-8506-4f07-ac1d-b682ad5a038b
< 1.2.21
MEDIUM 6.1 The Email Subscription Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '$email' paramete… wordfence
ce261415-870c-4300-85e8-b15a02c7eec5
< 1.8.35
MEDIUM 6.1 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
ce16175a-c58e-4432-80de-7872216ae273
< 6.4.1
MEDIUM 6.1 The ARforms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 6… wordfence
ce0c42bf-41d4-4fb5-af01-e98c4e4ec2fc
< 2.6.6
MEDIUM 6.1 The OPSI Israel Domestic Shipments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_i… wordfence
ce03e98d-7c29-405f-81bc-4a1114d9889d
< 150820
MEDIUM 6.1 wordfence
cdd4639a-683f-4267-828f-2fd404d9156f MEDIUM 6.1 The HSS Embed Streaming Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… wordfence
cdbad4b2-961a-41df-b284-14deb0a76677
< 12.6.4
MEDIUM 6.1 The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script… wordfence
cdaea9be-64ef-4567-ae17-08ae44293b5e
< 1.9.1
MEDIUM 6.1 The Easy Digital Downloads (EDD) Manual Purchases extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x be… wordfence
cdaaffa7-eb5e-4cb9-aa26-12cfeb7dabd1
< 1.0.0
MEDIUM 6.1 The External Media without Import plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error' p… wordfence
cdaa6b7c-bf38-44b5-9d83-2918cbedc683 MEDIUM 6.1 The Simple Video Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'analyti… wordfence
cda36dfc-385d-481a-b4f3-34f98b2b95a0 MEDIUM 6.1 The Email to Download plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
cd95eb77-dda1-4303-8d07-e77b7a11a4cc MEDIUM 6.1 The Delete Post Revision plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
cd8f5406-bbd2-44ab-9d98-3857216efc28
< 0.1.7
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in edit-post.php in the Flexible Custom Post Type plugin before 0.1.7 for WordP… wordfence
cd89c6ff-2737-4c48-8b0f-f305c4735775 MEDIUM 6.1 The WP BlipBot for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'BlipBotID' parameter in versions u… wordfence
cd8389f1-b70d-4d1a-bb25-e219c9099313
< 1.5
MEDIUM 6.1 The Newsletter Manager plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.4. This i… wordfence
cd8361c6-a235-4038-935c-3a4a37340764
< 1.8.3
MEDIUM 6.1 The Rankie plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.8.2 … wordfence
cd828557-94f6-4278-98ef-bcf4d1d86440 MEDIUM 6.1 The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
cd7fdfe6-f79b-4549-82f8-b4461a81c1f7 MEDIUM 6.1 The Video List Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
cd78a017-46b8-4335-b81d-480d4d0bcec2
< 2.9.10
MEDIUM 6.1 The ListingPro theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 2.9.10 due to insuf… wordfence
cd73cf64-289d-4401-bef7-9a4398a85055 MEDIUM 6.1 The Easy Captcha plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
cd7346e8-cd77-46dd-8e7d-694f65b6b62f
< 3.1.7
MEDIUM 6.1 The plugin Second Street for WordPress is vulnerable to Stored Cross-Site Scripting via the organization_id parameter in… wordfence
cd5a3d4b-6e8b-4abe-9f38-58accada2f57 MEDIUM 6.1 The Fast WP Speed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
cd552e86-5f0f-4203-b648-f069503b48e3
< 15.4
MEDIUM 6.1 The WPO365 | LOGIN WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross… wordfence
cd54d335-eb9c-4d0a-92c0-13462ef41a85
< 1.5.0
MEDIUM 6.1 The all-in-one-schemaorg-rich-snippets plugin before 1.5.0 for WordPress has XSS on the settings page. wordfence
cd53147f-2230-4b8b-a1a1-df377b334072
< 1.3.7.5
MEDIUM 6.1 The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the wooc… wordfence
← Prev 813 814 815 816 817 818 819 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top