🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 900 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7633b5cd-0e8f-4744-bfee-d6d54a44c143
< 2.124
MEDIUM 6.1 The MyCryptoCheckout plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url' parameter in v… wordfence
761c89a5-0176-45e6-87f1-0d510d271f18 MEDIUM 6.1 The JNews - Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
75f98731-f5a1-46aa-bf00-3b119a3b917e
< 8.7.4
MEDIUM 6.1 The NEX-Forms – Ultimate Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions… wordfence
75f964a8-a5eb-4990-a6d4-e911a20d0035
< 2.9
MEDIUM 6.1 The Real3D Flipbook plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘bookId’ parameter … wordfence
75ee17a7-2f7f-4102-97ab-7b348a24d6d7
< 2.5.3
MEDIUM 6.1 The XML for Avito plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
75b91e92-7c00-447d-80fa-6e20ca8df7ce MEDIUM 6.1 The WP CSV plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a parameter during CSV import in ver… wordfence
75aadbf5-763b-48cb-9d9e-fb8edb894d08
< 4.0.7
MEDIUM 6.1 The Survey Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
75a5853a-7497-4312-b7e1-e21b1425dc05
< 2.0.4
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the Sodahead Polls plugin before 2.0.4 for WordPress allow remote… wordfence
7594a0ed-cde4-4575-b155-e3717f0fee90 MEDIUM 6.1 The Jet Skinner for BuddyPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
758e035f-5713-4af0-a771-8214c753a9ba
< 4.4.3
MEDIUM 6.1 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Reflected Cross-Si… wordfence
755b53e4-051a-4a25-8fd9-fe10c28acc25
< 2.5.1.9
MEDIUM 6.1 There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re… wordfence
7555c5a5-54e2-4740-9b2f-84d526c9a5c1 MEDIUM 6.1 The Calendar Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
7541a595-aae4-49d2-862a-c1d1f4a1e6e5 MEDIUM 6.1 The Lexicata plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg withou… wordfence
752e3d68-001b-4523-9040-b1ef8fbffa7e
< 1.3.8.5
MEDIUM 6.1 The Asset CleanUp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
752d5de4-34c2-4a40-af47-69bd7e0ee48e
< 1.9.244
MEDIUM 6.1 The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-S… wordfence
752caefe-7e87-4d4f-89e0-fbd28e4076c4
< 4.3.26
MEDIUM 6.1 The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to… wordfence
752a07c4-ae88-4152-b449-68228a54604a
< 2.6.0
MEDIUM 6.1 The Custom Field Template plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
7528d520-7e91-49a8-b421-f27c9e82ed71 MEDIUM 6.1 The Network-Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
75126f4e-bb9d-4edb-b792-5456f3de614d
< 2.2.5
MEDIUM 6.1 The Starto theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and excluding, 2.2.5 d… wordfence
75105db1-e627-4cd4-a553-cdb5e8ef11c5
< 1.7.1
MEDIUM 6.1 The UpStore - Multi-Purpose WooCommerce WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Script… wordfence
75067f95-48b6-4c1d-8d8b-2601185b1f81
< 2.5.7
MEDIUM 6.1 The WPForms Google Sheet Connector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up t… wordfence
74ec7886-153a-44f2-9603-d4f1780132ad
< 2.5.1
MEDIUM 6.1 The WP Multistore Locator — WP Store Locator Plugin: Effortless Integration With Snazzy Maps plugin for WordPress is v… wordfence
74ec5f4c-1957-48f6-8bdb-4155b394b57c MEDIUM 6.1 The URL Shortener | Conversion Tracking | AB Testing | WooCommerce plugin for WordPress is vulnerable to Reflected Cro… wordfence
74e8259b-b702-4cdd-a0ec-4fed255069c9
< 5.3.0.1
MEDIUM 6.1 The Uncanny Automator Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
74e25ef2-ca4d-416e-8a9b-2ed09a93d1aa
< 1.1.5
MEDIUM 6.1 The Easy Digital Downloads (EDD) Lattice theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, … wordfence
← Prev 897 898 899 900 901 902 903 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top