🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 916 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
643cca2d-5a9a-4561-adf8-af9f0b3b0242 MEDIUM 6.1 The Embed Articles plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘API Key’ parameter … wordfence
642f0ad9-1085-4590-b736-9dd88440d047
< 1.4.0
MEDIUM 6.1 Invoices Add-on for iThemes Exchange before 1.4.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). wordfence
6423d84f-372d-4c6b-975f-3655dddc95a4 MEDIUM 6.1 The Related Posts via Taxonomies plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
6419b4a0-5729-4162-967b-54918551f5cb MEDIUM 6.1 The WP Database Audit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
640f0b06-9af2-4b79-8f87-97f93b2c51c0
< 2.3.7
MEDIUM 6.1 The Menu - Ordering - Reservations plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘redir… wordfence
6401fca3-0e2b-4fb2-8f5e-ef64c2e4a1c8
< 4.8
MEDIUM 6.1 The Smart Agenda – Prise de rendez-vous en ligne plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… wordfence
63ff56cf-0b64-491f-8629-8b7738adee10 MEDIUM 6.1 The Gallery Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_Query_… wordfence
63f588c6-6bad-44d2-a9d9-832d3a7d33ea
< 12.0.9
MEDIUM 6.1 The WP Statistics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions before 12.0.9 due to … wordfence
63e6d609-e221-4680-8706-187c5abdb968 MEDIUM 6.1 The Mopinion Feedback Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
63e167ef-9f03-45a8-b3dc-240ccf1ea6c3
< 1.6.8
MEDIUM 6.1 The Photo Gallery by 10Web plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions… wordfence
63e108f4-5d9d-4bcf-aef9-aa856f4241ea MEDIUM 6.1 The Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress is vulnerable to Cross-… wordfence
63c6eca6-9b55-48b5-ada3-97dd20d60f31
< 4.6.2
MEDIUM 6.1 The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in versi… wordfence
63b388ab-77e4-4bcd-9d7b-288bbff5aa21 MEDIUM 6.1 The HYDRO theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.8 due … wordfence
63b30d03-43d2-4696-aa36-8b39ec2c4ed0
< 1.2.17
MEDIUM 6.1 The Email Subscription Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several GET parame… wordfence
63af18df-a3e4-48e6-be84-15d33edf3b46
< 1.4.4
MEDIUM 6.1 The WP Easy Post Types plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ref' parameter foun… wordfence
63ac9de6-8713-4223-aaad-a70115d3bee7 MEDIUM 6.1 The Accordion Image Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.0.0.0 to 3.1.3. … wordfence
63a456e3-5bae-4a4b-850f-b35134de4cfb MEDIUM 6.1 The LBG Zoom In/Out Effect Slider for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters i… wordfence
6397f917-7d74-43f6-96b0-4aca6447eb86 MEDIUM 6.1 The Post-Plugin Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
639009f6-9877-45a9-b9f3-7256bc6f3360
< 3.0.8
MEDIUM 6.1 The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
638c86d4-973d-41fc-9d59-9d2e79f42f72
< 2.0.0
MEDIUM 6.1 The Invoice Payment for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up … wordfence
63832076-0f66-4d45-a020-85b7f2edec70 MEDIUM 6.1 The DocumentPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
6381ef3b-e46b-41d2-967d-5f29d749db6d MEDIUM 6.1 The Lexicata plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.… wordfence
635d6b0a-5895-4e50-a4ee-c7c6f40e897f MEDIUM 6.1 The Tidy.ro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1… wordfence
634c1e9d-85ba-4860-a3e4-a65bf3f23919
< 4.3.0.8
MEDIUM 6.1 The Tin Canny Reporting for LearnDash plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions u… wordfence
6341bdcc-c99f-40c3-81c4-ad90ff19f802
< 3.3.9.1
MEDIUM 6.1 The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'email', 'points', … wordfence
← Prev 913 914 915 916 917 918 919 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top