πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 906 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6e7f1fe6-0a23-48e1-a75f-f8c1c8d4f8e0 MEDIUM 6.1 The Gotcha | Gesture-based Captcha plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menu' p… wordfence
6e7bd966-9a98-4192-83d9-e1682ec00a02
< 1.3.1
MEDIUM 6.1 The EchBay Admin Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_ebnonce' parame… wordfence
6e6c56ab-b829-48b0-ba71-54b81173aaa3 MEDIUM 6.1 The Awesome Hooks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
6e5e957c-7b6f-4b69-b665-59292a32671e MEDIUM 6.1 The Display Post Meta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
6e57bcf3-6f9e-4746-a3d2-76ca36abb73f MEDIUM 6.1 The Essential WP Real Estate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an… wordfence
6e554ca0-2084-4ac0-b404-845a57123e00 MEDIUM 6.1 The Events Manager Pro – extended plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
6e54a627-7882-47de-ba36-1c34754bd64a
< 1.8.4
MEDIUM 6.1 The Houzez theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' and 'agent_name' parame… wordfence
6e520850-5cc7-40f8-9222-e7e50d21f347 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in rss.class/scripts/magpie_debug.php in the WP-Planet plugin 0.1 and earlier f… wordfence
6e4cc3e9-736c-47aa-b383-bd98377f51e1
< 1.0.25
MEDIUM 6.1 The ProductDyno plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
6e3e73b4-591d-4520-afd5-44e2bb76e4f1
< 1.0.1
MEDIUM 6.1 The Polls CP plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to 1.0.1 due to insufficient inpu… wordfence
6e3b68c8-151a-43d7-a953-051f57dec418
< 4.15.3
MEDIUM 6.1 The oik plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.15.… wordfence
6e3524a6-4f12-4640-96a0-da60afa0b770
< 3.1
MEDIUM 6.1 The Quick Paypal Payments plugin for WordPress is vulnerable to Cross-Site Scripting via the 'reference' and 'amount' pa… wordfence
6e02d123-701f-4502-ae6b-b313f39b3670 MEDIUM 6.1 The Site Editor Google Map plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
6e00b187-9a28-45fb-8d4d-e9401d739486
< 3.6.1
MEDIUM 6.1 The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting… wordfence
6deebf9a-6a28-4fb7-8f97-f40bf5e228aa MEDIUM 6.1 The AZ Content Finder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
6de64a12-0f73-40e9-bcd1-963dc6499ec4
< 1.1.3
MEDIUM 6.1 The Analytics Cat – Google Analytics Made Easy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du… wordfence
6dd6e04c-bac4-49c3-a934-7d3f43767684 MEDIUM 6.1 The Konzept theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and output … wordfence
6dd56a7f-1f33-44c2-a49a-9bdc88c081a9
< 2.9.11
MEDIUM 6.1 The ListingPro Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and exclu… wordfence
6dc91513-da96-4a82-9004-58ffddb453d5 MEDIUM 6.1 The Agile Video Player Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
6dbc64eb-1da6-4086-9fe1-3d9080bef12e
< 3.77
MEDIUM 6.1 The MyCurator Content Curation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'topic' para… wordfence
6dba72ee-7c38-4e10-9c0c-35d12aa83442
< 2.2.4
MEDIUM 6.1 The Form Data Collector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in… wordfence
6da0a85d-0c6f-40ae-8a3d-85222f0e7cc5
< 4.5.11
MEDIUM 6.1 The "Ivory Search – WordPress Search Plugin" plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via … wordfence
6d93ce6c-0139-472c-a5ec-21fdf33cd898
< 4.2
MEDIUM 6.1 The Titan Anti-spam & Security plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includi… wordfence
6d88433a-dff4-4524-9b1a-1ef929568a52
< 6.4
MEDIUM 6.1 The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to refle… wordfence
6d849f5a-f013-4b1d-b606-c7efefdfaca5
< 1.8.34
MEDIUM 6.1 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
← Prev 903 904 905 906 907 908 909 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top