🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 924 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5b720612-f3ec-4cc0-9cc8-b9e01421ca87 MEDIUM 6.1 The Post List With Featured Image plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
5b68e26d-1680-42ed-9b8e-23c80c19b1be
< 1.31
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before… wordfence
5b62aa7d-740f-447f-9086-5bc8286bc030
< 2.2
MEDIUM 6.1 The AI Search Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… wordfence
5b5fb356-df9a-45c1-a663-b762ca1b65c5
< 5.4
MEDIUM 6.1 The WPQA Builder WordPress plugin before 5.4, used as a companion for the Discy and Himer , does not sanitise and escape… wordfence
5b4f2862-c340-4637-accb-8f1ae6e432ea
< 1.6.3.9
MEDIUM 6.1 The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions u… wordfence
5b4db6bb-af81-496c-bd23-b777fc16c3e4
< 1.8.18.0
MEDIUM 6.1 The WP Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
5b4a2291-cf86-4d3f-8d6e-670b1b6ab124 MEDIUM 6.1 The Piotnet Addons For Elementor Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up… wordfence
5b48e0cc-5691-4df0-81ef-72f47d29ce30
< 1.7.15
MEDIUM 6.1 The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page befo… wordfence
5b3268c2-7cdd-4839-9859-42218d4d632b
< 2.0.0
MEDIUM 6.1 The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter … wordfence
5b3029c6-3a0f-4c83-8faf-f74d03852278
< 2.2.0
MEDIUM 6.1 The Grid Kit Premium plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 2.2.0 due to… wordfence
5b253378-beba-4e31-bf1f-0352fdf98ab5 MEDIUM 6.1 The Simple Header and Footer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
5b168045-9b68-43a7-89ce-d00a88bf8acd
< 2.1.0.13
MEDIUM 6.1 The WP Inventory Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘message’ para… wordfence
5af3acba-9620-4038-bc0c-4be1596573ff MEDIUM 6.1 The Instant Appointment plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
5af2f2a8-ab10-4623-abcd-234017424ab9
< 4.8.2
MEDIUM 6.1 The FoxyShop plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error’ parameter in versi… wordfence
5aeea62b-bd6c-4fe2-8c0f-8c9919688e87
< 2.29.19
MEDIUM 6.1 The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_p… wordfence
5aea8574-d90f-4359-a0c2-631019a22917 MEDIUM 6.1 The Ajax Custom CSS/JS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
5adc88e9-3fcd-4ad6-8eb9-1a111bf9cdc7
< 3.3.18
MEDIUM 6.1 XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes… wordfence
5adb9573-eb90-47a1-85c3-c2f60f69f545
< 1.7.5
MEDIUM 6.1 The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in vers… wordfence
5ad0354a-4a45-4933-9e04-58f6051ae551
< 3.9
MEDIUM 6.1 The video-player-youtube-vimeo plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
5ac30f59-45d0-4c28-ad90-e04452ee60dd MEDIUM 6.1 The Smart Notification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
5ab513d4-4cb9-4761-92af-a2224cb6a306
< 1.1.66
MEDIUM 6.1 The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms. wordfence
5ab2e2ae-6f46-4815-a2d2-407767bfaba8
< 3.0.6
MEDIUM 6.1 The PostX - Gutenberg Post Grid Blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘p… wordfence
5aaa97cc-4deb-43b6-957d-587834eca125 MEDIUM 6.1 The SVG Map Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
5aa9d6cb-18c8-42e4-a466-cc35c1dc5010
< 1.7.2
MEDIUM 6.1 The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-field-css para… wordfence
5aa2ff1f-c018-4c35-859e-f7e42134b937
< 1.8.8
MEDIUM 6.1 The WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and includ… wordfence
← Prev 921 922 923 924 925 926 927 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top