🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 907 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6d835d4c-0291-4f47-843c-e960f1e3676a MEDIUM 6.1 The AW WooCommerce Kode Pembayaran plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions … wordfence
6d7a86c2-16cf-4867-9b42-9db54c1c6ba6 MEDIUM 6.1 The Curated Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
6d5e640d-7ab9-4aea-a6a2-138cbbe0dbcc MEDIUM 6.1 The Flatsome theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.20.… wordfence
6d50b1c0-9687-4ce2-bfba-c2d6a2fc28dd MEDIUM 6.1 The Car Demon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_condition' parameter … wordfence
6d4c2944-28e8-4866-b4da-91cf12d9d115
< 2.3.42
MEDIUM 6.1 The PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip plugin for WordPress is vulnerable to Reflected Cross-… wordfence
6d48c52b-f42f-4c25-892f-3cce9ed8cbee
< 3.1.1
MEDIUM 6.1 The Count per Day plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘map’ parameter in ve… wordfence
6d43235b-9c5e-4d7f-99f0-28dcab4b2a91
< 2.12.9
MEDIUM 6.1 The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPr… wordfence
6d420e73-24d5-4da8-8257-e0c7f0273031
< 2.6.8
MEDIUM 6.1 The Five Star Restaurant Reservations plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'filt… wordfence
6d3668b3-2bf9-48fa-af14-d0917c8b99f5
< 1.0.2
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functio… wordfence
6d18706b-bc2a-4889-8057-ebc5805c6f10 MEDIUM 6.1 The Guten Free Options plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
6d126213-e342-4271-aca0-5cc47214ae8b
< 1.8.13
MEDIUM 6.1 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '… wordfence
6d063374-ecb2-41de-872d-18f94aac7e03
< 1.4.0
MEDIUM 6.1 The LifterLMS PayPal WordPress plugin before 1.4.0 does not sanitise and escape some parameters from the payment confirm… wordfence
6ce67488-3d4b-49c7-b9b9-b6e406a30468
< 2.2.9
MEDIUM 6.1 The Prague plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.8 … wordfence
6ce3d237-baed-405b-82f8-98ec95ed06fc MEDIUM 6.1 The WP Wall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.7.3… wordfence
6cd58adb-31cd-49e2-9c9d-e248b4b0a778
< 1.7.0
MEDIUM 6.1 The Product Catalog Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parame… wordfence
6cc308f4-c94f-48ae-9d65-0685236cdfbd
< 1.5.2
MEDIUM 6.1 The JobSearch WP Job Board WordPress Plugin is vulnerable to Reflected Cross-Site Scripting via the ‘location’ param… wordfence
6cbdd498-c0dd-48d1-ae2c-6d3df3ce2f03 MEDIUM 6.1 The FTP Sync – Theme, Media & Plugin Files plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
6cbb51fe-ae7f-4fe8-89ad-38f6d3238cea
< 4.3.22
MEDIUM 6.1 The Store Hours for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a… wordfence
6cb099ff-52c3-4ad6-994d-36275ebc0a5f MEDIUM 6.1 The Chalet-Montagne.com Tools plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… wordfence
6cae79d1-5ceb-4d34-9c9b-9cec4957cd6b MEDIUM 6.1 The DX-auto-publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
6cae5b10-516a-4b60-bc15-884ece5102cf
< 2.3.1
MEDIUM 6.1 The Simple Slideshow Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'name' paramet… wordfence
6cad85e1-9af0-44fa-97c7-a108b30891e2 MEDIUM 6.1 The Hacklog Down As PDF plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
6cab527f-bd67-4b67-8133-f085098d63dc
< 1.9.245
MEDIUM 6.1 The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cros… wordfence
6ca0681a-59ca-42e6-8ee2-574590fc3ae2
< 1.1.24
MEDIUM 6.1 The Header Footer Code Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several paramete… wordfence
6c9e5cd4-303c-48a7-aef8-20c804aa5985
< 2.2
MEDIUM 6.1 The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly saniti… wordfence
← Prev 904 905 906 907 908 909 910 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top