🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 910 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6ad70391-7ea0-49c0-ac5c-ecf7ddb3c948 MEDIUM 6.1 The Tags Cloud Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
6ad1d9f5-c224-4d28-8d73-439b3c5ca24f MEDIUM 6.1 The Like-it plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. … wordfence
6acc489c-283d-42a6-ab7e-89a178873c31 MEDIUM 6.1 The Theme Blvd Widget Areas plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
6ac3b00e-26f2-471d-a682-6cb4939e819e
< 1.2.3.8
MEDIUM 6.1 The WP PayPal plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.3.8 due t… wordfence
6ac2aa61-dd07-419c-8ff6-d862c39ab785 MEDIUM 6.1 The University quizzes online plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… wordfence
6aab08c1-20db-46a2-b93a-d864bb57bf4d
< 4.03
MEDIUM 6.1 The WP-TopBar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.02. T… wordfence
6aaa22f5-7304-4efc-9579-80ec053c2f7e
< 2.8.3.4
MEDIUM 6.1 The Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
6aa43e74-9911-4c7a-b01a-cb77c2c3fe99
< 12
MEDIUM 6.1 The Newspaper theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an AJAX action in versions up to, … wordfence
6aa2be6c-299e-4769-9070-a3c337bce990 MEDIUM 6.1 The OpenID plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.6.1 … wordfence
6a9b052a-1caf-4d39-ab91-c50605d86507 MEDIUM 6.1 The FoodMenu plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … wordfence
6a906f90-fac2-43cf-8f67-99f8862dc636
< 0.2.4
MEDIUM 6.1 The Ibtana - Ecommerce Product Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘po… wordfence
6a8dc0e3-ff3a-4abc-afca-eb1879603550
< 1.3.3
MEDIUM 6.1 The Pósturinn\'s Shipping with WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi… wordfence
6a8cb8ef-a2e5-47ef-8d8c-759ed83a015b
< 4.3
MEDIUM 6.1 The Import Content in WordPress & WooCommerce with Excel plugin for WordPress is vulnerable to Reflected Cross-Site Scri… wordfence
6a89c48d-eef2-4910-bd93-ef0a8482d814
< 1.2.1
MEDIUM 6.1 The Listings for Appfolio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
6a76116a-1e84-4114-9baa-3986be92d051
< 1.2.55
MEDIUM 6.1 The Calculated Fields Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters … wordfence
6a6390d2-58cd-468e-9936-e16954e2d3ee
< 2.2.3
MEDIUM 6.1 The Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting via the 'cid' parameter in versions up t… wordfence
6a4def27-eff6-43f3-93dc-e2472f858d1b MEDIUM 6.1 The Simple AL Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
6a1f2a7d-f91c-4dd2-b275-0e27f65498b1
< 2.2.3
MEDIUM 6.1 The Hero Maps Premium plugin 2.2.2 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index… wordfence
6a09e351-8326-4b31-bba5-5da34b417843
< 9.64
MEDIUM 6.1 The DZS Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ajax.php 'source' par… wordfence
6a03792a-7e14-41c6-a60c-cb5d389f7539
< 1.1.0
MEDIUM 6.1 Table Rate Shipping Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_… wordfence
69fd66db-5693-4976-96c0-60dbfeccd14f
< 2.1.4.2
MEDIUM 6.1 The InPost Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘imgurl’ parameter o… wordfence
69e92c75-5b14-43d9-a169-a1f8b51ab41d
< 3.0
MEDIUM 6.1 The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_f… wordfence
69e15a1b-4984-4889-8c57-a731a0334963
< 3.2.9
MEDIUM 6.1 The Ultimate Reviews plugin for WordPress is vulnerable to stored Cross-Site Scripting via the review functionality in v… wordfence
69ac1e37-4e31-4dce-a2d6-07a4299995c5
< 7.6.6
MEDIUM 6.1 The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg… wordfence
69a85ee3-1a26-443d-9ae8-6c6e965e7401 MEDIUM 6.1 The iSape plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.72 du… wordfence
← Prev 907 908 909 910 911 912 913 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top