πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 818 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cc1e480c-577a-467a-8297-747512286a39 MEDIUM 6.1 The RapidExpCart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0… wordfence
cc09b436-fa3d-4ed0-8b99-e14234332521
< 4.2.2
MEDIUM 6.1 The KBucket: Your Curated Content in WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… wordfence
cc030c9a-3cda-4eb8-9a7f-94a4b65a4272
< 2.0.0
MEDIUM 6.1 The Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.… wordfence
cbfbd7c2-7a46-4292-9173-f90298a7fcc4 MEDIUM 6.1 The eDoc Employee Job Application – Best WordPress Job Manager for Employees plugin for WordPress is vulnerable to Re… wordfence
cbe8cf1c-6105-4d38-b057-79566b1cd057 MEDIUM 6.1 The WP Contact Form III plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
cbd6a4ee-49ea-4008-83ac-1a3c3ccdd4d4
< 3.0.1
MEDIUM 6.1 The RSS Feed Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER['REQUEST_URI'] in … wordfence
cbd4983f-bf92-45c3-95a6-6f5e39bca228 MEDIUM 6.1 The Google Map Shortcode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
cbcf65b9-0114-46e6-a51f-61d606c68e5c
< 3.0
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress… wordfence
cbc86326-fced-4583-b128-9f592979cc9e MEDIUM 6.1 The Lewe ChordPress – ChordPro Text Formatter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all … wordfence
cbaa95d4-899f-49a0-a888-4ffee61c0335
< 1.6.1
MEDIUM 6.1 The Simple LDAP Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a… wordfence
cb91188b-71df-4aee-98f1-b77e0a33e01c
< 3.1.5
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in server/offline.php in the ActiveHelper LiveHelp Live Chat plugin … wordfence
cb84b71e-7d4d-4bd7-88cb-1b86d7023edb MEDIUM 6.1 The G Web Pro Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter i… wordfence
cb7ebe8c-2202-4206-bd2b-bf3129ff7178 MEDIUM 6.1 The Digihood HTML Sitemap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
cb6de4da-0d60-4332-be25-5521e430a4fa
< 6.2.1
MEDIUM 6.1 The Use Any Font | Custom Font Uploader WordPress plugin before 6.2.1 does not have any authorisation checks when assign… wordfence
cb6bfe31-0c90-4aca-8165-b30507f18ea5
< 3.8.4
MEDIUM 6.1 The Multivendor Marketplace Solution for WooCommerce – WC Marketplace plugin for WordPress is vulnerable to Reflected … wordfence
cb68f328-3090-487e-bb1f-95fe1571abd0
< 2.0.12
MEDIUM 6.1 Cross-site scripting vulnerability in wpDataTables Lite Version 2.0.11 and earlier allows remote attackers to inject arb… wordfence
cb62eefe-9993-43f7-b3ae-de47c0951bee
< 1.7.1
MEDIUM 6.1 The WPFactory Helper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_ar… wordfence
cb5c08ea-1321-42f8-aea2-49661396311b
< 3.7
MEDIUM 6.1 The RSS Includes Pages plugin plugin for WordPress is vulnerable to Cross-Site Scripting via the 'REQUEST_URI' parameter… wordfence
cb4bb127-360d-4f17-9da9-f7be17140ff3
< 1.1.8
MEDIUM 6.1 The Full Width Banner Slider Wp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term… wordfence
cb49eb5f-c1ff-4440-8b53-c2515e65da27
< 21.0.10
MEDIUM 6.1 The Shield Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in … wordfence
cb4681a5-d722-4585-97d3-370938c079a2
< 1.3.10
MEDIUM 6.1 wordfence
cb38d3bc-ae82-40ef-b20d-525d51432b1c
< 1.16
MEDIUM 6.1 The ImageInject plugin 1.15 for WordPress has XSS via the flickr_appid parameter to wp-admin/options-general.php. wordfence
cb35ad37-5a13-4610-95a1-6587e7f626fd MEDIUM 6.1 The AppMaps plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. … wordfence
cb1576f8-0586-4ad8-befb-b502d30fab52
< 3.3.5
MEDIUM 6.1 Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.3.4 via the itemsnumber parameter. wordfence
cb148264-c75e-4e73-95d7-3a06cdd8990e MEDIUM 6.1 The Login Configurator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
← Prev 815 816 817 818 819 820 821 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top