πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 920 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5f84814e-f7b7-4228-b331-63027a0770af
< 1.2.19
MEDIUM 6.1 The Email Subscription Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP_REFERER h… wordfence
5f82de4f-eff2-49b9-86ad-c75d709e9f10 MEDIUM 6.1 The Clinked Client Portal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
5f7dc2c7-1a23-4677-b331-951960e76d43
< 3.8.11
MEDIUM 6.1 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Reflected Cross-S… wordfence
5f7c4c26-ff77-4be0-946c-5480b4a28017
< 2.3
MEDIUM 6.1 The Home Villas | Real Estate WordPress Theme for WordPress is vulnerable to both Reflected and Stored Cross-Site Script… wordfence
5f75dfef-b30f-45a5-ba3e-cb82c1443800
< 0.8.1
MEDIUM 6.1 The Cornerstone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
5f6da693-4610-4875-aa14-102809309b8d
< 1.2.10
MEDIUM 6.1 The Cron Jobs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg witho… wordfence
5f6c53b5-e09c-48e1-9b5f-4871d566fc42 MEDIUM 6.1 The ANAC XML Render plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
5f6b88fb-1070-427b-a51f-23fbede3dd59
< 1.1.2
MEDIUM 6.1 The Under Construction, Coming Soon & Maintenance Mode plugin for WordPress is vulnerable to Server Side Request Forgery… wordfence
5f62045b-4fb7-4dde-8d3c-d04b4e5e4810
< 1.12.0
MEDIUM 6.1 The Easy Appointments plugin before 1.12.0 for WordPress has XSS via a Settings value in the admin panel. wordfence
5f59d905-0b43-4a63-b5da-273b051f201b MEDIUM 6.1 The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-ne… wordfence
5f550bac-b047-4276-bde5-c15bfd4ceb49
< 8.2.1
MEDIUM 6.1 The Media Library Folders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in … wordfence
5f4d57e4-1b82-45bb-9824-b7b2eaa73b6d
< 2.0.4
MEDIUM 6.1 The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable … wordfence
5f21a86b-52f4-4563-afce-32f1949ce5a1
< 1.2.137
MEDIUM 6.1 The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to Reflected … wordfence
5f1e0dfa-f99a-43d1-bdc9-6fc7a4ea381d
< 1.5.5
MEDIUM 6.1 The Smart Online Order for Clover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
5f126296-0a6e-4d47-8f1a-ce2aa097f21d MEDIUM 6.1 The Like & Share My Site plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
5efb2fbe-d839-4fb1-80bb-91adf0d39a2b MEDIUM 6.1 The Wtyczka SeoPilot dla WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
5ef842ad-3d23-4206-af3b-b3f55486766f
< 2.2.1
MEDIUM 6.1 The iTracker360 plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting … wordfence
5ef65205-6477-482c-8f7c-380709744691
< 1.5.3
MEDIUM 6.1 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Reflected Cross-Site Scr… wordfence
5eeebd5f-6062-4ddd-a7bf-6afbeeed568e
< 2.02
MEDIUM 6.1 The Share This Image plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
5eeae0eb-bc24-4a34-b393-e84831edaba6
< 3.1.11
MEDIUM 6.1 wordfence
5ee9183c-be0c-4b1f-9cf5-25866c16ef40 MEDIUM 6.1 The Invelity SPS connect plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
5ee3416b-d6df-4f8b-834b-4e78516c00ba MEDIUM 6.1 The WP Backup Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
5ee19031-1e48-43b6-b492-980f2610f6cc
< 2.2.6
MEDIUM 6.1 ProductX – Gutenberg WooCommerce Blocks – WooCommerce Builder, Wishlist for WooCommerce, Products Comparison, Quick … wordfence
5ed9f7a1-54ef-4f88-b89c-756b8b646254 MEDIUM 6.1 The WP-Walla plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all vers… wordfence
5ec1ce79-bc10-4b04-8e49-15e16e6730a8
< 2.5.0
MEDIUM 6.1 The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it i… wordfence
← Prev 917 918 919 920 921 922 923 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top