🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 921 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5eba6825-9a3a-4af5-8d8a-9439ab374cc7
< 3.0.39
MEDIUM 6.1 The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter… wordfence
5eb66ca3-768e-4d8c-a0fa-74e78250aee3
< 4.2.9
MEDIUM 6.1 The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm… wordfence
5eab077f-0aeb-4dec-9ed2-8a09c4450d06 MEDIUM 6.1 The WP Lyrics plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.4… wordfence
5e9ba1cb-62f5-4d6a-9727-ae62bb0edb98
< 1.2.6.2
MEDIUM 6.1 Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 Wo… wordfence
5e95ded5-ebf7-4ed3-a194-7e7e494d0c40 MEDIUM 6.1 The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2c… wordfence
5e959ac0-e5ac-4d28-8161-311d952b993c
< 3.9.6
MEDIUM 6.1 The Essential Real Estate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
5e74ee0d-f03d-4139-a192-2a45d5f619dc MEDIUM 6.1 The ShopConstruct – Product Catalog, Shopping Cart and eCommerce solution for Store plugin for WordPress is vulnerable… wordfence
5e69c365-65fd-4001-93c3-5df023e8e05b MEDIUM 6.1 The Dezdy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0… wordfence
5e618864-e862-4d4f-aa28-3e2fb78882fc
< 1.6.22
MEDIUM 6.1 The iPanorama 360 WordPress Virtual Tour Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi… wordfence
5e600744-7f5a-483a-9df9-cf90b22b3a9e MEDIUM 6.1 The WP Compare Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
5e5bdc92-e682-4121-9ba5-167742f61138
< 3.7.3
MEDIUM 6.1 The Custom 404 Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in ver… wordfence
5e45b5d3-0f55-45b2-a289-42d37af266c1 MEDIUM 6.1 The Swift Calendar Online Appointment Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
5e3e6ca7-83fb-4558-aa90-0a10432af2d8 MEDIUM 6.1 The Lime Developer Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
5e36b6bd-20d9-433f-beb7-82077b09beee MEDIUM 6.1 The Videos plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.… wordfence
5e364f0c-17ea-4962-92d3-35bf5eb666ad
< 1.4.15
MEDIUM 6.1 The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-… wordfence
5e3593e8-3840-4db0-8269-61bbcb50d569
< 1.4.5
MEDIUM 6.1 The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_jav… wordfence
5e21524e-2470-49e1-983a-a62a0ae478f6
< 4.0.38
MEDIUM 6.1 The Fast Secure Contact Form plugin before 4.0.38 for WordPress allows fs_contact_form1[welcome] XSS. wordfence
5e043348-c0aa-418f-9120-dcf470f92123 MEDIUM 6.1 The Yahoo! WebPlayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
5dfb8937-848d-4ce6-a90c-03b75f7951a1 MEDIUM 6.1 The WordPress Filter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
5df2dfcd-2fda-4f09-bd77-f437422d20bb
< 1.5.12
MEDIUM 6.1 The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter… wordfence
5df238dd-6269-4ee0-a0f4-12bdb74f74e8
< 6.2.8
MEDIUM 6.1 In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display o… wordfence
5dea4293-0496-4cee-9d8a-c15beaa51b14 MEDIUM 6.1 The WHMpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.2-… wordfence
5de8bc53-612f-4cee-b10c-bc24fc67bcf0 MEDIUM 6.1 The Feedpress Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
5dd270c6-31e5-4005-9c5f-d29e1f2f5faa MEDIUM 6.1 The Conversion Helper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
5dbebce4-599b-4241-aa9a-3d2486a57d52 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in js/window.php in the Wikipop plugin 2.0 and earlier for WordPress allows rem… wordfence
← Prev 918 919 920 921 922 923 924 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top