πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 913 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
67acf726-bf56-472e-aa7c-316bcd8a56fb
< 2.0.101
MEDIUM 6.1 The RentSyst – CRM solution for fleet management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
67aaf9fa-e92b-42f2-94ac-f27c5d073002
< 1.5.2
MEDIUM 6.1 The WP-Hijri plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'month' and 'year' parameter i… wordfence
6782d8b3-32f9-42e1-874c-35a1e93ffde0 MEDIUM 6.1 The Woo Custom Emails for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wcemails_edit' parameter in… wordfence
6781c76b-bfcb-43b3-8275-5b4c2aa1fe07
< 5.1.5
MEDIUM 6.1 The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via avada_portfolio_category_slug parameter s… wordfence
6781b7b7-c11a-4328-8d14-ffafc2ccb127
< 1.3.2.1
MEDIUM 6.1 The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'emailf' parameter on the … wordfence
6778d6ad-951f-4002-9999-9bfa08bc925f MEDIUM 6.1 The No Disposable Email plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
676d4cac-9df7-4aaa-9aca-a23a46974019 MEDIUM 6.1 The Document Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
676cb664-dd9d-4b6e-80d6-c2afb2298541
< 1.49
MEDIUM 6.1 The ClickSold IDX for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜id’ parameter in versions u… wordfence
67678796-61d4-423f-b8f4-3f5667184d06
< 6.4.9.5
MEDIUM 6.1 The Quiz Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.… wordfence
675b029a-70f2-434d-8d14-0b9e9c02bd6e
< 7.95
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress … wordfence
6753a37b-7242-4895-a439-f726ad835f61
< 2.4
MEDIUM 6.1 The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the hi… wordfence
6745be2e-d151-452a-8e65-0db2409dd54d
< 2.3.9
MEDIUM 6.1 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t… wordfence
6728fca7-f66d-4b8a-a16f-db60a315b434 MEDIUM 6.1 The Address Bar Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL Path in all version… wordfence
6714ccff-ab6f-4222-96eb-7f442e94f225
< 7.6.4
MEDIUM 6.1 The Visual CSS Style Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
67147f28-b362-46f9-9d26-7fde05dab33b
< 1.4.1
MEDIUM 6.1 The Prestige theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 1.4.1 due to insuffic… wordfence
670efa9a-168b-4c9b-9c8a-727dd3a13a3b MEDIUM 6.1 The Passwordless WP – Login with your glance or fingerprint plugin for WordPress is vulnerable to Reflected Cross-Site… wordfence
6702c762-14c1-490a-92e4-313b785b3407
< 1.2.3
MEDIUM 6.1 The WP REST API plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.2 due t… wordfence
67008179-2e79-4d20-b36e-b63047fdedd8
< 4.0.10
MEDIUM 6.1 The Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.0.… wordfence
66ed3f4d-1977-487a-942e-3dd599586957
< 1.7
MEDIUM 6.1 The Intense WP "WP Jobs" plugin 1.5 for WordPress has XSS, related to the Job Qualification field. wordfence
66c7c6d1-8077-4b9c-a26c-631e18917a43 MEDIUM 6.1 The SEO Tools plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.0… wordfence
66c49614-8b57-4889-b6a2-c0cead7375d9 MEDIUM 6.1 The Real Time Validation for Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versi… wordfence
66bca09b-7f53-4e7a-a58c-a28ad6a4825e
< 1.04
MEDIUM 6.1 The Download buttons for Youtube videos plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions… wordfence
66b6443a-3bd0-4f45-8ad3-424d11ec24e1
< 1.2
MEDIUM 6.1 The No Page Comment plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER['REQUEST_URI'], wh… wordfence
66b279f3-ff44-4d81-b626-39489111d35d MEDIUM 6.1 The Maniac SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
66a65270-182b-44b1-968b-4fc2d8de1ea6
< 3.2.7
MEDIUM 6.1 The Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter. wordfence
← Prev 910 911 912 913 914 915 916 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top