πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 899 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
77476bad-e9a4-4266-b07e-b402b33cc27a
< 1.2.6
MEDIUM 6.1 The ReCaptcha Integration for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the … wordfence
77440d6e-b660-433b-9953-c1f92644302e
< 1.3.5
MEDIUM 6.1 The subscriber plugin before 1.3.5 for WordPress has multiple XSS issues. wordfence
773f2b16-3a70-4d06-9a9c-77a787596e37
< 1.4.8
MEDIUM 6.1 The Reebox theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 1.4.8 due to insufficie… wordfence
773b5a79-017a-4e16-b563-3aa2939fa179
< 1.2.30
MEDIUM 6.1 The Martins Free & Easy SEO BackLink Link Building Network – Improve Rankings & Traffic plugin for WordPress is vulner… wordfence
772e9b2b-b2d5-4950-804b-d0914004710c MEDIUM 6.1 The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
770f3c25-effb-40ea-bd1c-7874c456ab0e MEDIUM 6.1 The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allow… wordfence
770d1b3f-45f1-40f6-80b7-808c633d2be7
< 6.0.3
MEDIUM 6.1 The Checkout with Cash App on WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '… wordfence
7703c73d-a854-4e29-b99e-4f9a414b7579 MEDIUM 6.1 The Bootstrap Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
76ff305f-dc92-44ec-90bb-b504ed9b930e MEDIUM 6.1 The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) plugin for WordPress is vulnerable to Reflected… wordfence
76f32441-ce6a-472d-a437-c284cb91eb8c MEDIUM 6.1 A cross-site scripting (XSS) vulnerability in the wp-concours plugin through 1.1 for WordPress allows remote attackers t… wordfence
76e941b1-6c64-496e-863b-406375e59a7c MEDIUM 6.1 The WhatsApp Chat for WordPress and WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in … wordfence
76e185c3-d62b-42f7-a943-0498da2d76ce
< 3.3.3
MEDIUM 6.1 The persian-woocommerce-sms plugin before 3.3.3 for WordPress has ps_sms_numbers XSS. wordfence
76d57372-9fb5-4166-bfa9-835e3ff7b755
< 1.9.11
MEDIUM 6.1 The Tutor LMS WordPress plugin before 1.9.11 does not sanitise and escape user input before outputting back in attribute… wordfence
76c6fa7e-9250-464e-a7ee-8a6814e18446 MEDIUM 6.1 The WP Login Attempt Log plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
76b3b5b7-fefe-44fb-a30e-c55226d4aaea
< 2.2
MEDIUM 6.1 The BrainCert – HTML5 Virtual Classroom plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versio… wordfence
76b0c41c-c825-4ac2-8a7f-4b1a54f21f0b MEDIUM 6.1 The Smart Start theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and out… wordfence
76ac20e0-c4d1-40ad-8f15-70aad547f08f MEDIUM 6.1 The Expose theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and output e… wordfence
769fbe66-fcf5-4b16-8cc3-7c9bc561257a
< 4.65
MEDIUM 6.1 The "The WP Remote WordPress Plugin" plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in v… wordfence
7689d8f4-9311-40f6-a4c3-117abfcf91e1 MEDIUM 6.1 The Open edX LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
7681f984-d488-4da7-afe1-988e5ad012f2
< 2.8.7
MEDIUM 6.1 The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress… wordfence
766e34a9-ed95-4049-ba48-0bf69134e4ba
< 3.2.0
MEDIUM 6.1 The EventPrime plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the keyword and ep_filter_date p… wordfence
76639a75-65f9-4c0c-9182-f8de470da431 MEDIUM 6.1 The MultiMailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
765df8f4-438c-41b6-ac74-494f1b74cf33
< 3.6.1
MEDIUM 6.1 The Cookiebot | GDPR/CCPA Compliant Cookie Consent and Control plugin for WordPress is vulnerable to Reflected Cross-Sit… wordfence
764af015-6741-4290-a2fe-95389eb28f17 MEDIUM 6.1 The TheFox theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.9.76 … wordfence
76345533-ec81-4a6e-bb20-12449dd63a27
< 5.0.13
MEDIUM 6.1 The AddThis plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.0.12 due to i… wordfence
← Prev 896 897 898 899 900 901 902 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top