ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 919 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
60fd52f1-9a31-440f-b6ec-d11cc9d0feed MEDIUM 6.1 The Uptime Robot plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
60dedbdb-1411-4b71-91ef-b2a98cdbb53c MEDIUM 6.1 The Anon theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.10 du… wordfence
60ae8b8f-bc65-40df-b6ae-4ec8e328dbe5
< 2.11.1
MEDIUM 6.1 The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard plugin for WordPress is vulnerable to Reflected Cro… wordfence
6091e396-8cd8-4c56-89cb-7699adb3d798
< 4.7
MEDIUM 6.1 The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via … wordfence
607ea767-8a9f-414a-b6ed-af8335256e60 MEDIUM 6.1 The Diamond theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.4.8 … wordfence
607d1a6e-2277-4960-a5bd-95e94c510856
< 2.0
MEDIUM 6.1 The FoodBakery theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9… wordfence
607a5846-4112-4f0d-b353-68903b2a4cb8
< 1.9.0
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.7.0 plugin for WordPress allow remote attacker… wordfence
605c6c53-6920-42ba-8784-b3a186bbf821 MEDIUM 6.1 The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] var… wordfence
60584089-723c-40de-9719-e8434969308a
< 3.0.7
MEDIUM 6.1 The Silvasoft boekhouden plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
6042e3d9-cced-43b8-8b3c-eaca9855b842
< 2.4.8
MEDIUM 6.1 The Email Log WordPress plugin before 2.4.8 does not escape the d parameter before outputting it back in an attribute in… wordfence
603846de-5d3b-498f-844b-306d80df80da
< 1.0.8
MEDIUM 6.1 The Two Factor Authentication (2FA , MFA, OTP SMS and Email) plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
603087d1-49cb-4080-b0ef-14f04dce3fed MEDIUM 6.1 The Social Author Bio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
602d1302-138f-4ee4-a36c-179f24a2bf0b MEDIUM 6.1 The Bannerlid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versi… wordfence
60116e60-ebf3-4f32-b536-52ce2a9672df
< 3.4.3
MEDIUM 6.1 The RoyalSlider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3… wordfence
60030ee9-ad5d-4d84-a019-1906b20ebbc1 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in picasa_upload.php in the WP-Picasa-Image plugin 1.0 and earlier for WordPres… wordfence
6002fd39-b25b-4e15-837e-5430757d8cb1 MEDIUM 6.1 The Contact Form 7 Material Design plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
5ffbd0d8-c70a-4385-a990-7b558a147935 MEDIUM 6.1 The Global Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
5ffb31a5-a692-4817-ad46-cf804b97d480
< 1.6.6
MEDIUM 6.1 The Tribulant Slideshow Gallery plugin before 1.6.6 for WordPress has XSS via the id, method, Gallerymessage, Galleryerr… wordfence
5ff7ccb7-08fc-43de-8579-2a30d28e2de7
< 6.5.1
MEDIUM 6.1 The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'editrecord' para… wordfence
5fec449b-76ab-441c-9683-35620e4ebce9 MEDIUM 6.1 The ZMSEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.14.1.… wordfence
5fe983d6-ad48-460f-ba5d-f6de19f06be4
< 1.0.7
MEDIUM 6.1 The NewStatPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'limitquery' parameter in … wordfence
5fdf6407-388c-4fb4-b00d-7ed389a9067d
< 1.1.6
MEDIUM 6.1 The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … wordfence
5fdb8e77-1323-43a0-a012-04d983390de1
< 4.4.1
MEDIUM 6.1 The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to Re… wordfence
5f8e0021-f305-45c1-b658-405ad22334ac
< 2.2.2
MEDIUM 6.1 Cross-site scripting vulnerability in WordPress plugin spam-byebye 2.2.1 and earlier allows remote attackers to inject a… wordfence
5f8a13e3-f6f5-4673-b223-95eb11465756
< 5.8002
MEDIUM 6.1 The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'step' parameter in all ver… wordfence
← Prev 916 917 918 919 920 921 922 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top