🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 917 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
633a9cbf-451d-4fd1-822b-ef8966ff9a1a
< 2.3.3
MEDIUM 6.1 The Activity Log Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ page’ parameter in v… wordfence
6338620f-925a-4226-9557-313a7f8a6b6a
< 3.2.1.11184
MEDIUM 6.1 The WPFront User Role Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘changes-sav… wordfence
630310c5-0434-4988-8bc5-09ae0cb27cbf MEDIUM 6.1 The WP e-Customers Beta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
62f7cd02-6859-4fed-a09a-45b418f1308c
< 1.0.7
MEDIUM 6.1 The Kundgenerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
62ebb1d0-e1ee-43ea-a673-15ba72a9f0c9
< 5.0.0
MEDIUM 6.1 The Church Admin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 5.0.0 due to ins… wordfence
62eb222d-0723-428e-b7fc-6baf67213d90 MEDIUM 6.1 The WP jQuery Persian Datepicker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
62eb1ff6-8e98-4843-b697-21ce74e2aad8 MEDIUM 6.1 The Wizhi Multi Filters by Wenprise plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
62e903c6-36f1-45cb-8164-23a8d1ca3966 MEDIUM 6.1 The "Goodnews – Responsive WordPress News/Magazine | News / Editorial" theme for WordPress is vulnerable to Reflected … wordfence
62e56040-ef01-464f-9451-2b762b652be3
< 2.9.2
MEDIUM 6.1 The MyWorks WooCommerce Sync for QuickBooks Online plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
62a6fc85-db3c-4696-8102-d0247daae56c
< 3.1.7
MEDIUM 6.1 The StaffList plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in version… wordfence
629fe670-f48b-4eb6-86f9-e1bac3771530 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in smilies4wp.php in the WP Smiley plugin 1.4.1 for WordPress allows remote aut… wordfence
629df2b3-1312-475c-8064-8b61bdef135a
< 2.5
MEDIUM 6.1 The BP Messages Tool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
629c00fe-aaf3-493c-ac1b-9cbcf74b32cf MEDIUM 6.1 The Pets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4.1 du… wordfence
629868b2-d4c7-4bfa-968f-480e4450c164 MEDIUM 6.1 The Affiliate Links Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
6278c70a-7b25-45f0-bc64-ecb231e1bf55
< 2.1.23
MEDIUM 6.1 The Contact Bank – Contact Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
6277495a-f3a6-4f5a-9cec-2c0b293015b6 MEDIUM 6.1 The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … wordfence
626ea1f2-df66-4903-9cbe-7186cf62291b
< 1.6.1
MEDIUM 6.1 The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET paramete… wordfence
6257739a-cd7c-4797-882a-016a01fe84b4
< 7.13.52
MEDIUM 6.1 The Social Share, Social Login and Social Comments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
6251d0f6-b536-4122-8fdf-bb77665a4f41
< 1.2.84
MEDIUM 6.1 The DPD Baltic Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_value' para… wordfence
624d9627-0ffc-409f-beb7-60e80177aa9b
< 1.0.4
MEDIUM 6.1 The TheRoof theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.3 … wordfence
624af5e1-dc40-4d33-bfac-1a409b81a096
< 4.0.4
MEDIUM 6.1 The SpeakOut! Email Petitions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ par… wordfence
624a87c7-d43e-48d5-8489-d4f7b3ea10da
< 3.5.8
MEDIUM 6.1 WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute Java… wordfence
6208afdb-502c-44e8-b50a-22fa87ee80df
< 3.1
MEDIUM 6.1 There is an XSS vulnerability in the File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path… wordfence
62029ce5-ab97-4594-93e6-469ef5692320
< 2.2.5
MEDIUM 6.1 The Restrict plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in versions u… wordfence
61ec7f34-d18d-4ee8-adbf-ec1219772e67
< 1.5.19
MEDIUM 6.1 The Molla - eCommerce HTML5 Template theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up … wordfence
← Prev 914 915 916 917 918 919 920 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top