🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 909 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6b8a0cf1-2be7-4d57-8ef6-137035ceb422 MEDIUM 6.1 The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_keywords and neuvoo_location XSS. wordfence
6b84df5b-ff93-43b3-b9e4-cf963cf2af10
< 2.8.3
MEDIUM 6.1 The List all posts by Authors, nested Categories and Title plugin for WordPress is vulnerable to Cross-Site Scripting in… wordfence
6b8038e8-a196-43f0-a250-db95aced944a MEDIUM 6.1 The Featured Page Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
6b7cf194-f7e8-4776-ab14-77d9ad05b966 MEDIUM 6.1 The Dot html,php,xml etc pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
6b7877c8-0001-48e3-ab8a-eb1f2bebcbe1
< 8.42
MEDIUM 6.1 The UpSolution Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
6b76734b-96ed-4643-b11b-bba0f0f228ab MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in cached_image.php in the Featurific For WordPress plugin 1.6.2 for WordPress … wordfence
6b75ffbe-ef47-4f37-811d-2d501c22b56d
< 1.5
MEDIUM 6.1 The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
6b635525-7e0a-4bb5-84fd-f8694c352b0b MEDIUM 6.1 The Mass Custom Fields Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
6b6250d0-8f5e-4283-8d16-0b2f467e1224
< 1.6.2
MEDIUM 6.1 The gregs-high-performance-seo plugin before 1.6.2 for WordPress has XSS in the context of an old browser via 'submenu' … wordfence
6b4b05a8-3a32-4fa9-9ff5-a2a62b11a05d
< 3.5.8.2
MEDIUM 6.1 The WebLibrarian plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in version… wordfence
6b4087e9-071c-4cfc-b23d-ae8dd0059a2b
< 1.9.1
MEDIUM 6.1 The Live Scores for SportsPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘lsfs_mat… wordfence
6b3fc000-57e7-4be4-959f-27dac9717b9e
< 1.5.94
MEDIUM 6.1 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected C… wordfence
6b28908b-ffad-46d5-b6de-6b9c7bbe0134 MEDIUM 6.1 The JobRoller theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tester’ parameter in vers… wordfence
6b26dd2e-3d0b-4c6b-8819-6d1e437207fd MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional Wo… wordfence
6b213baa-8508-4eb2-ac09-d320e2b4276c
< 1.3.5
MEDIUM 6.1 The Grid Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘grid_id’ parameter in ve… wordfence
6b1e20ee-4c25-4174-a809-b4fdecc44fd1 MEDIUM 6.1 The Savyour Affiliate Partner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
6b11dc40-e0aa-4a82-b8a3-90ef72ae6871
< 1.22.5
MEDIUM 6.1 The Shipping with Venipak for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all ve… wordfence
6b0f85d5-6ef7-4e6d-a03b-75672fca654c
< 3.6
MEDIUM 6.1 The Moova for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the lat parameter in the … wordfence
6b06667f-cda1-4177-b168-c7d26a0cd815 MEDIUM 6.1 The Coalition theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and outpu… wordfence
6b019674-cfe9-4f59-8ec2-4844cbca3c93 MEDIUM 6.1 The Tabulate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … wordfence
6afa4ca1-5284-4c05-acdc-292fab332fe0
< 1.9.2
MEDIUM 6.1 The WeMusic theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.1 … wordfence
6af1224e-0ed3-4770-96c0-c15cc895d36d
< 1.11.1
MEDIUM 6.1 The Post Status Notifier Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
6ae1f758-0990-46c3-bd77-3e43bb14d03f MEDIUM 6.1 The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripti… wordfence
6adab3e7-c437-4832-a015-0ebf0976a78a MEDIUM 6.1 The Insert Code plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… wordfence
6ad84e6e-5498-4bf1-b662-15b7628ceba2
< 6.5.4
MEDIUM 6.1 The Track Google Analytics 4, Facebook Pixel & Conversions API via Google Tag Manager for WooCommerce plugin for WordPre… wordfence
← Prev 906 907 908 909 910 911 912 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top