πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 905 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6fac6a6f-07ce-4c2d-b223-c661a4dc530a MEDIUM 6.1 The CG Scroll To Top plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
6fa6a784-f1d4-47d7-9bf8-64b3c4340328
< 3.5.10.1
MEDIUM 6.1 The JetSearch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5… wordfence
6f9764e1-0187-4f6e-827c-84daac81872f MEDIUM 6.1 The Content Grid Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
6f8b75a1-f0f2-445b-a1c7-1628916470d3 MEDIUM 6.1 The Winters theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up t… wordfence
6f77f10b-f142-4859-a941-0fbde6ef7fdb
< 2.27.5
MEDIUM 6.1 The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights … wordfence
6f73b12b-813d-49fa-84a0-3345023a16c6
< 2.7.5
MEDIUM 6.1 The RSVP and Event Management plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includin… wordfence
6f6883e4-3de6-4ca9-a26c-0b4f3bd5b70f
< 3.8.0.9
MEDIUM 6.1 The RegistrationMagic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
6f598cfc-4d41-4d22-95f0-47efdb7d07a2
< 4.7.3
MEDIUM 6.1 The GD bbPress Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu… wordfence
6f57d5ec-bc2d-4dc4-b1b2-c5919986d198 MEDIUM 6.1 The personal-authors-category plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in a… wordfence
6f38d7b7-6df6-47a2-a9ba-87ef1f039e44
< 2.9.31
MEDIUM 6.1 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Ty… wordfence
6f1856bc-6d57-416e-86e9-9114bbbe5c8d
< 3.5.4
MEDIUM 6.1 The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) plugin for WordPress is vulnerable to Cross-Site Scripti… wordfence
6ef18e0e-8fad-464b-943b-54fbbe169ce9
< 2.7.10
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the uDesign (aka U-Design) theme 2.3.0 before 2.7.10 for WordPress allows re… wordfence
6eef5549-3f89-4d6f-8c4e-6e4ee6082042
< 1.0.4
MEDIUM 6.1 wordfence
6eeb6df1-9857-47a2-ad7d-f1eb082e9448 MEDIUM 6.1 The ULTIMATE TABLES plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
6ee48355-33a3-4689-8b09-2affee6adf21
< 3.5.1
MEDIUM 6.1 The WP2LEADS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.… wordfence
6edb6604-9da8-421e-933b-bac02b179bd0
< 1.3.1
MEDIUM 6.1 The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… wordfence
6ece9b6d-6802-44b9-9ead-1563286f4ff3 MEDIUM 6.1 The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pag… wordfence
6eccc8cd-5f5f-45a9-90fb-8491b238a3f6 MEDIUM 6.1 The Data Dash plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
6ebdc324-9709-4e09-96ff-d1ea1d8bb63f MEDIUM 6.1 The WordPress Events Calendar Registration & Tickets plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
6eb99654-c0f4-4c75-9b9d-f3075db623fc
< 3.2.6
MEDIUM 6.1 The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to Reflected C… wordfence
6ea9dda4-d667-46f3-893b-a1ae60b6ba75 MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the WP Ultimate Email Marketer plugin 1.2.0 and possibly earlier … wordfence
6ea36692-2bf3-490d-8293-7de6dcc5e5c9
< 2.3.3
MEDIUM 6.1 The PublishPress Capabilities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a form action URL… wordfence
6e90fe49-4ead-4468-b3cc-30040e4f278f
< 4.9.24
MEDIUM 6.1 The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template a… wordfence
6e845eae-dae9-40bb-aca9-21afaa40576d
< 21.8.0.100
MEDIUM 6.1 The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via… wordfence
6e80e3ac-331a-480f-94ca-06d62230cd80 MEDIUM 6.1 The LMB^Box Smileys plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
← Prev 902 903 904 905 906 907 908 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top