🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 897 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7a2f1cc7-f3f6-4a69-8b15-dfa13b136334 MEDIUM 6.1 The Epeken All Kurir Plugin for Woocommerce Full Version plugin for WordPress is vulnerable to Cross-Site Request Forger… wordfence
7a1f91a3-6b8d-4be4-817c-9c88d2349723
< 2.3
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD bbPress Attachments plugin before 2.3 for WordPre… wordfence
7a1044f0-a49a-4746-b4bf-20f7de46f8c9
< 3.6.12
MEDIUM 6.1 The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-S… wordfence
79fcf18e-39f7-42f2-90e4-3a5bac3382e0
< 3.2.43
MEDIUM 6.1 The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and includi… wordfence
79f03bfe-dd7e-47e7-9e6f-4539d26cc101 MEDIUM 6.1 The YSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versi… wordfence
79af711e-d044-447e-9802-8be648a3843d
< 2.7.3
MEDIUM 6.1 The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
79ae682a-c048-427c-abf8-3ecbccc9c95c
< 3.6.6
MEDIUM 6.1 The Social Media Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage param… wordfence
799975aa-44fe-48dc-8ac9-469c89a03c67 MEDIUM 6.1 The Donations Made Easy – Smart Donations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the re… wordfence
79844b53-5527-42e2-8363-db0eb73d1f6c MEDIUM 6.1 The CultBooking Hotel Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
797faa73-401d-492c-a99d-0724df57b6e9
< 9.5
MEDIUM 6.1 The easy-social-share-buttons3 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown param… wordfence
7948dc00-6ee7-4458-9636-d6909913d3a3 MEDIUM 6.1 The WP-PManager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
793df609-77bb-47fd-8383-93884675f217
< 1.1.1
MEDIUM 6.1 The CRM Perks Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
7938e9f4-d905-4968-b811-23eb8ec4dd9d
< 5.8015
MEDIUM 6.1 The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI'] par… wordfence
792d6c70-4c17-493a-bb4a-08a55e8240d3
< 2.3.8
MEDIUM 6.1 The rsvp plugin before 2.3.8 for WordPress has persistent XSS via the note field on the attendee-list screen. wordfence
7921c896-dca4-460d-90dc-458eb0d82334 MEDIUM 6.1 The Choices theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to insufficient input sanitization a… wordfence
790c1783-3cc3-4ba4-a261-e92abb03d14a MEDIUM 6.1 The Admin Customization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
78fef897-fcef-4238-9925-0ce610ee7686
< 1.14.1.3
MEDIUM 6.1 The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data. wordfence
78f90656-49cb-4f13-8488-45a601048ade
< 6.0.0
MEDIUM 6.1 The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in… wordfence
78f08c2b-c6e4-431e-bbbd-5dd082b29195
< 0.2.9
MEDIUM 6.1 The Age Verify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.… wordfence
78f04982-7f42-4c10-9fad-2584a26a4c79
< 1.2.3
MEDIUM 6.1 The Multilanguage by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘categor… wordfence
78c19531-550d-4b97-a30d-adcaad43b53b
< 1.3.19
MEDIUM 6.1 The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea para… wordfence
78b2e66b-7ef1-40f7-a65e-0ed979197a4c
< 1.3.6
MEDIUM 6.1 The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
78b12984-72ce-493f-b1ef-200e96c6eb57 MEDIUM 6.1 The Explicit theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all version… wordfence
7870badf-a1c8-4a47-adac-d6535ab81d79
< 2.1.18
MEDIUM 6.1 The CURCY plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without a… wordfence
7863f63c-11b5-43ac-9d68-8eb9925cdf7e
< 2.5.1.9
MEDIUM 6.1 There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re… wordfence
← Prev 894 895 896 897 898 899 900 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top