🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 904 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
711b2889-8d12-4f7c-88e7-d3bb79e9c800 MEDIUM 6.1 The Simple Balance theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in vers… wordfence
711a7307-0a7a-4640-8d88-5c370b0156de
< 1.36
MEDIUM 6.1 The Custom Search plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including,… wordfence
71130bae-d871-43b5-81cd-b8459c8db316 MEDIUM 6.1 The Google Map Generator for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘address’ parameter i… wordfence
71110eaa-d412-4082-95c2-39d245c768b3 MEDIUM 6.1 The Workbox Video from Vimeo & Youtube Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in al… wordfence
710e1c2c-4b5d-412c-950d-b5e530abf3a7
< 6.0.15
MEDIUM 6.1 The Essential Addons for Elementor – Popular Elementor Addon With Ready Templates, Advanced Widgets, Kits & WooCommerc… wordfence
710bdf8d-b06f-4b50-9f76-129c49d32dba MEDIUM 6.1 The WP VTiger Synchronization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
7102fb7f-eb69-4c2f-956b-61ceace968e4 MEDIUM 6.1 The Soundy Background Music plugin 3.9 and below for WordPress has Cross-Site Scripting via soundy-background-music\temp… wordfence
70ee7a29-69b0-49a8-a60e-7364ede4490a MEDIUM 6.1 The Universal Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
70e1e2b8-90cc-40eb-94ae-1d4e5b2259f3 MEDIUM 6.1 The Akismet htaccess writer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
70db1a8e-ebff-4505-9e43-1ce48e94f3c5
< 9.5.2
MEDIUM 6.1 The WP Statistics plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 9.5.1 due… wordfence
70d05b9e-bead-42f9-9d19-c92c8e6440cd
< 3.5.8
MEDIUM 6.1 The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter i… wordfence
70c6bfb9-46d4-43ed-a6b4-9fe1fc9aa945 MEDIUM 6.1 The Link2Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0… wordfence
70c1ee04-cfb1-4819-95ab-497e814da16f
< 1.1.8
MEDIUM 6.1 The WP Test Email plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg w… wordfence
70ac8447-3d42-4577-8d46-528966a9f002
< 1.1.6
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the WP-Cron Dashboard plugin 1.1.5 and earlier for WordPress allows remote a… wordfence
705c2322-bb52-4337-b0dd-6bf04bd1b0e0
< 2.3.68
MEDIUM 6.1 The Listivo - Classified Ads WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the… wordfence
702dca65-fa8c-48c7-89e4-cba4b151e2c4 MEDIUM 6.1 The Permalinks Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter … wordfence
7020d5a1-a4a6-489c-8615-bc7898553bcf
< 2.4.3.2
MEDIUM 6.1 wordfence
701d6bee-6eb2-4497-bf54-fbc384d9d2e5
< 2.8.6
MEDIUM 6.1 The BuddyForms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in vers… wordfence
70110d50-853d-4972-a5a0-b5c566ba7de6
< 5.8.12
MEDIUM 6.1 The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, p… wordfence
7007c8db-b111-4c0f-a6e2-6b99971444aa MEDIUM 6.1 The Soho Hotel theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
6ff637c7-677f-4d70-b3cb-770d0a47e691 MEDIUM 6.1 The Centangle-Team plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
6fd9cfbe-2bf4-4218-a29d-c4b70ed132af
< 1.0.9
MEDIUM 6.1 Cross-site scripting vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to inject arbitrary web scr… wordfence
6fc92b8f-6794-461a-b6b6-598de21f5e2d
< 7.2.5
MEDIUM 6.1 The WoodMart theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.2.4… wordfence
6fc1be7b-cd9e-4dc0-81b2-4bae171fa1cd MEDIUM 6.1 The RDP inGroups+ plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
6fbde737-0730-49a4-a84e-a9c5e0e32af5
< 8.2.6
MEDIUM 6.1 The WP VR plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'active_tab', 'scene', and 'hotsp… wordfence
← Prev 901 902 903 904 905 906 907 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top