🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 932 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
535af5fa-891b-4d21-ab13-c4ef68dd339b
< 3.8
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the LeagueManager plugin 3.7 for WordPress allow remote attackers… wordfence
53356d15-8db0-4015-addf-9bf66446e81f
< 2.20.29
MEDIUM 6.1 The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘rt’ parame… wordfence
53071503-0edd-458f-a24d-107d576695ed MEDIUM 6.1 The yawpp plugin through 1.2.2 for WordPress has XSS via the field1 parameter. wordfence
52ff0d94-82cc-4ebd-9481-6d29f00fcc02
< 4.3.10
MEDIUM 6.1 The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to … wordfence
52fde632-f3a4-48d5-8c2c-c42b9d20dcb7 MEDIUM 6.1 The RapidExpCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.… wordfence
52f5c90a-e4ba-4212-83e0-281b8624dda0
< 1.3.4
MEDIUM 6.1 The Social Rocket plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
52ee1a7d-33c6-48aa-a2ac-62a1246439a9
< 8.5.5
MEDIUM 6.1 The WP eStore plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Category Editing in all versions … wordfence
52e2f1b9-d240-4813-9124-51bd6b047553
< 1.6.1
MEDIUM 6.1 The HTML Forms – Simple WordPress Forms Plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Script… wordfence
52e04362-2e14-4d50-867d-df9263fa1ac9 MEDIUM 6.1 The Marekkis Watermark-Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… wordfence
52dd9f90-5654-42f4-a2b7-350d90d91e2d MEDIUM 6.1 The SEO, Nutrition and Print for Recipes by Edamam plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… wordfence
52dd12eb-5f50-4048-a0e1-23d181400dad MEDIUM 6.1 The all-in-one-box-login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
52c2837e-8947-4ce9-bda5-e0c2f831fb36 MEDIUM 6.1 The URL Shortener by MyThemeShop plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’… wordfence
52bd9946-dccc-427a-9abd-0b7153e7484f
< 5.4
MEDIUM 6.1 The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting v… wordfence
52ac7e85-0a01-41f0-b753-7858a859705f
< 1.4.2
MEDIUM 6.1 The Email Encoder plugin for WordPress is vulnerable to Cross-Site Scripting via 'email' and 'display' parameters in ver… wordfence
52ac7ccf-89fd-47d3-ba61-7bcf84908a57
< 1.2.66
MEDIUM 6.1 The contact-form-to-email plugin before 1.2.66 for WordPress has XSS. wordfence
529e6d96-84d6-4a41-960d-4d201abb8de4 MEDIUM 6.1 The DeepDigital – Web Design Agency WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
5294f427-738c-444e-acf6-abc452629f64 MEDIUM 6.1 The Abundance theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and outpu… wordfence
528a00f3-13dd-499d-9814-b772f535a07c MEDIUM 6.1 The CaptionPix plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
52842812-d7c5-4244-b1ee-cf6197a75c4e
< 1.1.19
MEDIUM 6.1 The F4 Post Tree plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
527dd711-4eb6-4432-92a1-6d458885ec9e MEDIUM 6.1 The ePaper Lister for Yumpu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
52759823-6c04-4f2f-a1a7-a23e44d45d29 MEDIUM 6.1 The Pinpoll plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.0.0… wordfence
526a1b9c-953b-4ad7-91e1-d2e480b967ac
< 1.0.6
MEDIUM 6.1 The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which… wordfence
52696d42-b522-47d3-9a59-92078145c2be
< 1.0
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Webhammer WP Custom Fields Search plugin 0.3.28 for WordPress allows rem… wordfence
5253fe2b-040b-417c-b257-0cb59ee5aa6e
< 3.4.2
MEDIUM 6.1 The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in … wordfence
52527a50-8912-4040-a937-1eb771e245d4 MEDIUM 6.1 The Wordpress Auto Spinner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
← Prev 929 930 931 932 933 934 935 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top