🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 914 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
66a3346c-47dd-4286-b3f9-01c3f5a70ac4 MEDIUM 6.1 The Porto theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.6.2 du… wordfence
66a2a159-5748-49bd-9204-e85e1c6729df
< 1.02
MEDIUM 6.1 The Woo Email Control plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘recipient’ param… wordfence
669fa0eb-9b75-4508-82e7-b1a991f3b01a
< 2.4
MEDIUM 6.1 The WP Visitors Tracker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
66950509-ce2a-42fe-a8b2-2a92a1b573c3 MEDIUM 6.1 The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in al… wordfence
668afa62-1326-4067-8d0a-f16788e85ae5
< 2.1.16
MEDIUM 6.1 The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it … wordfence
66717800-31ab-4e68-979a-4967dd2caeb8
< 1.7.5.10
MEDIUM 6.1 The Participants Database plugin for WordPress is vulnerable to Cross-Site Scripting via the 'Name' paremeter in version… wordfence
6662c336-c8b6-4017-835f-a91f1abda400 MEDIUM 6.1 The Code Insert Manager (Q2W3 Inc Manager) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all v… wordfence
6654094f-a503-464c-910f-3dff643a49ba MEDIUM 6.1 The Essential WP Real Estate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of URLs… wordfence
664f43a6-6461-42ce-a3e4-2277c01a0efb
< 0.5.77
MEDIUM 6.1 The Co-marquage service-public.fr plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of… wordfence
664d265b-7b35-4c61-b48b-d051b7fb5ebd
< 2.7.4
MEDIUM 6.1 The 胖鼠采集(Fat Rat Collect) 微信知乎简书腾讯新闻列表分页采集, 还有自动采集、自动发布、… wordfence
66351875-42d7-45f4-a47f-22e3e26b2770
< 1.4.01
MEDIUM 6.1 The Calendar Event Multi View for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘'start' and 'end'… wordfence
662eb948-e1d2-4a11-a139-16d277cd5c53 MEDIUM 6.1 The Virtual Bot plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
661016f0-be26-4318-bf84-30e47a8fe15a MEDIUM 6.1 The modal-survey plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
65f89b65-7231-469e-bd7d-cf6a1d962652
< 2.2.14
MEDIUM 6.1 The WP Telegram Widget and Join Link plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up… wordfence
65f4e5e1-4c2e-4943-aa84-4caa61e14bc2
< 3.24
MEDIUM 6.1 The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘smc_settings… wordfence
65f4de84-1472-489b-9247-0ceb53369d2b MEDIUM 6.1 The Persian Woocommerce SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
65f30cd4-1d47-4ebe-a6de-acdb3a813c9c MEDIUM 6.1 The Dynamic QR Code Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parame… wordfence
65ea592e-3340-4559-8b6e-871a4e603296 MEDIUM 6.1 The Tydskrif theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1… wordfence
65e68147-84cc-4b2d-85b9-e5b7bde2e604
< 1.3.46
MEDIUM 6.1 A cross-site scripting (XSS) vulnerability in the SabaiApp Directories Pro plugin 1.3.45 for WordPress allows remote att… wordfence
65cb692f-b518-4581-ba63-c43eb450c56e
< 1.1.0
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote… wordfence
65bf0897-4d90-41e7-89a3-69845ea54ce5
< 0.18.7
MEDIUM 6.1 The Theater for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_que… wordfence
6591c2a5-d238-418f-be00-1bb5c2fa77e9
< 2.8.4
MEDIUM 6.1 wordfence
658ccd08-5f46-4a11-8d86-38b49027f83e
< 1.3.6
MEDIUM 6.1 The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the… wordfence
6577d7e4-af15-4b12-b8c9-94e231493b3f
< 1.13.3
MEDIUM 6.1 The WP ERP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.13.2… wordfence
657226b4-db55-4859-8f38-65b4ace11f4a
< 6.0
MEDIUM 6.1 The ND Shortcodes plugin for WordPress is vulnerable to arbitrary options update in versions up to, and including 5.9.1,… wordfence
← Prev 911 912 913 914 915 916 917 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top