🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 911 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
69a2bce2-d731-41b9-840a-147c64cc7b3c MEDIUM 6.1 The Interactive US Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
69a0262e-6061-4139-ac59-b1a13dd2f147
< 0.43.6
MEDIUM 6.1 The Sermon Browser plugin for WordPress is vulnerable to Cross-Site Scripting via the 'file_name' parameter in versions … wordfence
699a83e0-1b92-4f16-9e8f-40576afaaa01
< 11.42
MEDIUM 6.1 The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
699392b4-8270-47b5-90c1-5280d1389586 MEDIUM 6.1 The WP Widget Changer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']… wordfence
69903c2e-749a-4a7d-99a2-b63c26d4170a MEDIUM 6.1 The Eunoia theme for WordPress is vulnerable to Cross-Site Scripting in all versions due to insufficient input sanitizat… wordfence
69885963-b103-473d-8751-d79f45e88e94 MEDIUM 6.1 The Coming Soon Countdown plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
698728b9-a4ba-4fd1-8ad4-37c148fb3d95 MEDIUM 6.1 The WPAMS - Apartment Management System for wordpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
69711a11-96c2-458d-87f5-a3d8152ab20c MEDIUM 6.1 The Bulk Block Converter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
696960f4-ed10-4b61-8292-ef407544ba69 MEDIUM 6.1 The Canvasflow for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
6966cf31-721b-4759-a4c2-4b20c6a7053d
< 3.2.2.0
MEDIUM 6.1 The Universal Video Player - Addon for WPBakery Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
69435cb6-9591-45bb-86e3-eaf1a9bc46f9
< 2.9.19
MEDIUM 6.1 The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including… wordfence
691c0f3b-b723-4310-b4df-ed3e1db9d548
< 2.3.7
MEDIUM 6.1 The WP Plugin Info Card plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘slug’ paramete… wordfence
691b080c-052a-4967-a251-98a17038448d MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in test-plugin.php in the Swipe Checkout for WP e-Commerce plugin 3.… wordfence
6918bbc2-ad9d-4d3b-8cdf-bf906bae180c MEDIUM 6.1 The Save & Import Image from URL plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… wordfence
69150437-dfd6-436a-b100-99f5001c7fe7
< 1.12.0
MEDIUM 6.1 iThemes Exchange before 1.12.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). wordfence
6913a08d-c997-4f58-bec1-eeae08a5b6c9 MEDIUM 6.1 The WPOptin – AI-Powered Top Bars, PopUps & Lead Generation plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
6903e37e-5251-47bb-8023-755821af4689
< 1.4.12
MEDIUM 6.1 The User Avatar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'uid' parameter in versions… wordfence
69025975-9fb7-47a7-9dea-68f4c01d5fdc
< 2.1.2
MEDIUM 6.1 The Email Encoder – Protect Email Addresses WordPress plugin before 2.1.2 has an endpoint that requires no authenticat… wordfence
6902180a-dd74-4c50-bce2-75cef88241e9 MEDIUM 6.1 The Advance WP Query Search Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up t… wordfence
6901648a-b54f-4d20-bc22-65731fab13b9 MEDIUM 6.1 The WordPress Hashtags plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
68fe0f74-96d7-4d5b-99a2-dff4f1c9d30b MEDIUM 6.1 The Plugmatter Pricing Table Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `email` param… wordfence
68f2e124-73c5-4ab2-ae0f-b4ca29d8312e MEDIUM 6.1 The Extensions for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
68d9b56b-2460-48d5-95ca-b64e65592b16
< 2.0.24
MEDIUM 6.1 The Polldaddy Polls & Rating for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘polldaddy-ratings-… wordfence
68d71bd0-176c-4eee-99c2-9b591d6f70d3
< 1.3.1910240
MEDIUM 6.1 The ECPay Logistics for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'CVSSto… wordfence
68aba88f-e7f9-42d7-9dea-045e7fef7056
< 5.0.06
MEDIUM 6.1 The google-language-translator plugin before 5.0.06 for WordPress has XSS. wordfence
← Prev 908 909 910 911 912 913 914 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top