ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 929 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
56a06949-be02-439d-90ba-77803e7b76ae
< 2.0
MEDIUM 6.1 The Eazy Under Construction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
569c8faf-bd2a-4c61-a8c7-d4cab36e5727
< 0.5.1
MEDIUM 6.1 The Ready! Coming Soon plugin for WordPress is vulnerable to Cross-Site Scripting and Cross-Site Request Forgery in vers… wordfence
569a19dd-9d56-4518-b271-123346506348 MEDIUM 6.1 The LionScripts: Site Maintenance & Noindex Nofollow Plugin plugin for WordPress is vulnerable to Cross-Site Request For… wordfence
568d9b75-3ac9-47eb-b958-4f1781a6edc4
< 1.3.0
MEDIUM 6.1 The woo-popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
567d62ec-e868-45e2-b07a-8cc661d7c5e1
< 8.2.3
MEDIUM 6.1 The WP Customer Area plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all… wordfence
566935a5-b296-49cc-8df0-1850f8680caa MEDIUM 6.1 The e-shops plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.4… wordfence
56527389-37f9-485f-876d-b31ae3b45f75 MEDIUM 6.1 The 无觅相关文章æ’ä»¶ plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
564a1631-fe33-40f6-a0eb-37868be07171
< 2.4.4
MEDIUM 6.1 The simple-job-board plugin before 2.4.4 for WordPress has reflected XSS via keyword search. wordfence
5646eb5b-caf0-413c-a1a8-f0c6a5fa5114
< 2.4
MEDIUM 6.1 The megamenu plugin before 2.4 for WordPress has XSS. wordfence
562f058a-d4dc-4b59-b11e-d942f4c8de52 MEDIUM 6.1 The Custom Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
5628fb28-03fd-407d-874e-7801b17098f7
< 4.2
MEDIUM 6.1 The Custom Share Buttons with Floating Sidebar plugin for WordPress is vulnerable to Cross-Site Scripting in versions up… wordfence
56259eda-db70-4a26-a08e-e4d998dbe50d
< 3.6.8
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Atahualpa theme before 3.6.8 for WordPress allows remote attackers to in… wordfence
562456ac-a113-4b3d-bc5d-6dedde635d5e
< 1.7.5
MEDIUM 6.1 The WP Twitter Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all … wordfence
561c8bcf-30b0-4ee6-b507-4cacf22c1e58
< 2.0.18
MEDIUM 6.1 The Ultimate Member (aka ultimatemember) plugin before 2.0.18 for WordPress has XSS via the wp-admin settings screen. wordfence
561b2487-0d6a-4cc7-b41c-0e88f45d3038
< 3.1.5
MEDIUM 6.1 The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family pa… wordfence
560548c7-8007-4e2c-bd34-78fcb7b43eb1
< 1.11
MEDIUM 6.1 The Instabot: Chatbot to Increase Conversions on WordPress. Try for Free plugin for WordPress is vulnerable to Cross-Sit… wordfence
55c586a0-bb91-4702-a9f2-d7503f247da3
< 3.3.7
MEDIUM 6.1 The Magic Post Thumbnail plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ids’ paramete… wordfence
55b08fca-65af-4535-aa94-a9bfaef67b4c
< 3.2.1
MEDIUM 6.1 The Easy Pricing Tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the multiple parameters… wordfence
559bf74a-1c34-4e77-b395-005150ab5e6e MEDIUM 6.1 The WP Talroo plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all ver… wordfence
559b7250-5b10-4a01-925e-73ed4fa7ca3d
< 1.1
MEDIUM 6.1 The Essence theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unspecified parameter in versions… wordfence
559a94d8-527d-48b3-a917-461ebfa012bc
< 3.0.0
MEDIUM 6.1 The Filestack Official plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fstab' and 'filesta… wordfence
55893639-3b47-4ddc-b896-4b66341a4eba
< 1.5.5
MEDIUM 6.1 The Cart66 Lite :: WordPress Ecommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s… wordfence
5580e3b7-31fd-4895-9af6-94129224abab MEDIUM 6.1 The Leads CRM plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0… wordfence
5579957a-ad45-4518-ad3c-16b3841a301d MEDIUM 6.1 The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
55773c6c-85e8-4023-8dd6-4feb0f6254b2
< 1.57
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.5… wordfence
← Prev 926 927 928 929 930 931 932 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top