🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 912 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
68a87e74-597d-4d2c-9900-9c46dffe334f
< 1.2
MEDIUM 6.1 The Dynamic URL SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
688d30ac-9b30-4298-a935-316e5503a31b MEDIUM 6.1 The SpiderFAQ plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
688353c9-e4e5-4717-9651-15d05248554f MEDIUM 6.1 The Footer Putter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all v… wordfence
6870e237-2c2f-46c7-bf00-b3f1bedb8d8d MEDIUM 6.1 The Ad-minister plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.6 via the… wordfence
686430ed-8b26-4c6a-9e49-4a2cc5f1f7dd
< 1.22.24
MEDIUM 6.1 The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versio… wordfence
6857b90e-7570-4c1c-836e-08f367bb485b
< 4.9.5
MEDIUM 6.1 The DotLife theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 4.9.5 due to insuffici… wordfence
6845b506-3d38-47f6-9348-d7931e65707a
< 6.3.2
MEDIUM 6.1 The WooCommerce PensoPay plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pensopay_action' … wordfence
6840add4-62db-4b99-b48b-0b51aa2451b8
< 3.2
MEDIUM 6.1 The Product Enquiry for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’… wordfence
68263c7d-6da0-46b2-bb78-45acf615359d
< 3.0
MEDIUM 6.1 The Yoast Duplicate Post plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.… wordfence
680b2194-0c5e-4d5c-86d8-4c1e8de378d7
< 1.8.5
MEDIUM 6.1 The Master Addons for Elementor WordPress plugin before 1.8.5 does not sanitise and escape the error_message parameter b… wordfence
680865ad-41f3-4c7a-889c-464b69872b72 MEDIUM 6.1 The LSD Google Maps Embedder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
68042416-efa6-4814-a8d9-c74ab652c4ed
< 4.4
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the ZenLite theme before 4.4 for WordPress allows remote attackers to inject… wordfence
68042314-14a4-4c9d-940c-2e2735f95d9a MEDIUM 6.1 The Flexo Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
68014bb5-b2ef-4e2f-9c47-85e555ded5a7
< 1.8.3.1
MEDIUM 6.1 The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is… wordfence
67fc4141-7875-459b-98d8-d14e0a6f566c
< 2.2.8
MEDIUM 6.1 The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'eid' parameter in all versions… wordfence
67f9f44b-badc-48d5-b1d9-11cd6501fa9b
< 1.8.25
MEDIUM 6.1 Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection. wordfence
67eb25d7-8412-437c-942b-e003f8f0a187
< 2.1.7
MEDIUM 6.1 The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Reflec… wordfence
67e86c46-36f7-4aef-ab7b-33a2dd7e40d5 MEDIUM 6.1 The Zielke Design Project Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
67e3096e-7641-4f95-9e16-c1b45028c7eb
< 3.0.71
MEDIUM 6.1 The eCommerce Product Catalog plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘product_ca… wordfence
67e2636a-1a5d-4526-aace-b276faf321a7
< 8.0.16
MEDIUM 6.1 XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admi… wordfence
67e1f412-3b3d-4b36-b4ff-557c4790362a MEDIUM 6.1 Reflected XSS in wordpress plugin e-search v1.0 via date-from parameter. wordfence
67e0f32c-7556-4568-b651-6a9d43e48566 MEDIUM 6.1 The ZD Scribd iPaper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
67d2e1c7-dbd3-4195-8bdb-3b85b25bfa52
< 2.1.0
MEDIUM 6.1 The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Script… wordfence
67cab267-f776-4519-a882-4c6bdce65e1b MEDIUM 6.1 The WP Social Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
67b14116-8708-401c-a037-4976a360256a
< 3.5.8
MEDIUM 6.1 The WordPress Bitcoin Payments – Blockonomics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via… wordfence
← Prev 909 910 911 912 913 914 915 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top