🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 918 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
696960f4-ed10-4b61-8292-ef407544ba69 MEDIUM 6.1 The Canvasflow for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
6966cf31-721b-4759-a4c2-4b20c6a7053d
< 3.2.2.0
MEDIUM 6.1 The Universal Video Player - Addon for WPBakery Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
69435cb6-9591-45bb-86e3-eaf1a9bc46f9
< 2.9.19
MEDIUM 6.1 The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including… wordfence
691c0f3b-b723-4310-b4df-ed3e1db9d548
< 2.3.7
MEDIUM 6.1 The WP Plugin Info Card plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘slug’ paramete… wordfence
691b080c-052a-4967-a251-98a17038448d MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in test-plugin.php in the Swipe Checkout for WP e-Commerce plugin 3.… wordfence
6918bbc2-ad9d-4d3b-8cdf-bf906bae180c MEDIUM 6.1 The Save & Import Image from URL plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… wordfence
69150437-dfd6-436a-b100-99f5001c7fe7
< 1.12.0
MEDIUM 6.1 iThemes Exchange before 1.12.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). wordfence
6913a08d-c997-4f58-bec1-eeae08a5b6c9 MEDIUM 6.1 The WPOptin – AI-Powered Top Bars, PopUps & Lead Generation plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
6903e37e-5251-47bb-8023-755821af4689
< 1.4.12
MEDIUM 6.1 The User Avatar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'uid' parameter in versions… wordfence
69025975-9fb7-47a7-9dea-68f4c01d5fdc
< 2.1.2
MEDIUM 6.1 The Email Encoder – Protect Email Addresses WordPress plugin before 2.1.2 has an endpoint that requires no authenticat… wordfence
6902180a-dd74-4c50-bce2-75cef88241e9 MEDIUM 6.1 The Advance WP Query Search Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up t… wordfence
6901648a-b54f-4d20-bc22-65731fab13b9 MEDIUM 6.1 The WordPress Hashtags plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
68fe0f74-96d7-4d5b-99a2-dff4f1c9d30b MEDIUM 6.1 The Plugmatter Pricing Table Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `email` param… wordfence
68f2e124-73c5-4ab2-ae0f-b4ca29d8312e MEDIUM 6.1 The Extensions for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
68d9b56b-2460-48d5-95ca-b64e65592b16
< 2.0.24
MEDIUM 6.1 The Polldaddy Polls & Rating for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘polldaddy-ratings-… wordfence
68d71bd0-176c-4eee-99c2-9b591d6f70d3
< 1.3.1910240
MEDIUM 6.1 The ECPay Logistics for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'CVSSto… wordfence
68aba88f-e7f9-42d7-9dea-045e7fef7056
< 5.0.06
MEDIUM 6.1 The google-language-translator plugin before 5.0.06 for WordPress has XSS. wordfence
68a87e74-597d-4d2c-9900-9c46dffe334f
< 1.2
MEDIUM 6.1 The Dynamic URL SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
688d30ac-9b30-4298-a935-316e5503a31b MEDIUM 6.1 The SpiderFAQ plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
688353c9-e4e5-4717-9651-15d05248554f MEDIUM 6.1 The Footer Putter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all v… wordfence
6870e237-2c2f-46c7-bf00-b3f1bedb8d8d MEDIUM 6.1 The Ad-minister plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.6 via the… wordfence
686430ed-8b26-4c6a-9e49-4a2cc5f1f7dd
< 1.22.24
MEDIUM 6.1 The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versio… wordfence
6857b90e-7570-4c1c-836e-08f367bb485b
< 4.9.5
MEDIUM 6.1 The DotLife theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 4.9.5 due to insuffici… wordfence
6845b506-3d38-47f6-9348-d7931e65707a
< 6.3.2
MEDIUM 6.1 The WooCommerce PensoPay plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pensopay_action' … wordfence
6840add4-62db-4b99-b48b-0b51aa2451b8
< 3.2
MEDIUM 6.1 The Product Enquiry for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’… wordfence
← Prev 915 916 917 918 919 920 921 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top