🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 939 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
52e04362-2e14-4d50-867d-df9263fa1ac9 MEDIUM 6.1 The Marekkis Watermark-Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… wordfence
52dd9f90-5654-42f4-a2b7-350d90d91e2d MEDIUM 6.1 The SEO, Nutrition and Print for Recipes by Edamam plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… wordfence
52dd12eb-5f50-4048-a0e1-23d181400dad MEDIUM 6.1 The all-in-one-box-login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
52c2837e-8947-4ce9-bda5-e0c2f831fb36 MEDIUM 6.1 The URL Shortener by MyThemeShop plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’… wordfence
52bd9946-dccc-427a-9abd-0b7153e7484f
< 5.4
MEDIUM 6.1 The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting v… wordfence
52ac7e85-0a01-41f0-b753-7858a859705f
< 1.4.2
MEDIUM 6.1 The Email Encoder plugin for WordPress is vulnerable to Cross-Site Scripting via 'email' and 'display' parameters in ver… wordfence
52ac7ccf-89fd-47d3-ba61-7bcf84908a57
< 1.2.66
MEDIUM 6.1 The contact-form-to-email plugin before 1.2.66 for WordPress has XSS. wordfence
529e6d96-84d6-4a41-960d-4d201abb8de4 MEDIUM 6.1 The DeepDigital – Web Design Agency WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
5294f427-738c-444e-acf6-abc452629f64 MEDIUM 6.1 The Abundance theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and outpu… wordfence
528a00f3-13dd-499d-9814-b772f535a07c MEDIUM 6.1 The CaptionPix plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
52842812-d7c5-4244-b1ee-cf6197a75c4e
< 1.1.19
MEDIUM 6.1 The F4 Post Tree plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
527dd711-4eb6-4432-92a1-6d458885ec9e MEDIUM 6.1 The ePaper Lister for Yumpu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
52759823-6c04-4f2f-a1a7-a23e44d45d29 MEDIUM 6.1 The Pinpoll plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.0.0… wordfence
526a1b9c-953b-4ad7-91e1-d2e480b967ac
< 1.0.6
MEDIUM 6.1 The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which… wordfence
52696d42-b522-47d3-9a59-92078145c2be
< 1.0
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Webhammer WP Custom Fields Search plugin 0.3.28 for WordPress allows rem… wordfence
5253fe2b-040b-417c-b257-0cb59ee5aa6e
< 3.4.2
MEDIUM 6.1 The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in … wordfence
52527a50-8912-4040-a937-1eb771e245d4 MEDIUM 6.1 The Wordpress Auto Spinner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
5247b658-c655-4855-ad98-695071b0ede6 MEDIUM 6.1 The UberSlider Ultra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
523cfed4-0422-40f3-8d81-d7862bcb1792 MEDIUM 6.1 The MyTube PlayList plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘addplaylistid’ par… wordfence
52343971-65a8-4efd-ad6d-521936730b27 MEDIUM 6.1 The chatplusjp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
52293a10-4240-4a6b-a05b-33675a4ed6b6 MEDIUM 6.1 The WC1C plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without ap… wordfence
5224233f-6cb4-4fd9-b25b-e32db612cb7f MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in vncal.js.php in the VN-Calendar plugin 1.0 and earlier for WordPr… wordfence
520730e0-e085-4bbf-a1c7-497b9ae2da3c MEDIUM 6.1 The BP Profile as Homepage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
5204d111-3dd5-4dd0-bf1a-79ec2900b4d8
< 4.9.6
MEDIUM 6.1 The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
51e1a30e-774e-4478-be34-486ed4142a7d
< 3.4.3
MEDIUM 6.1 Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead t… wordfence
← Prev 936 937 938 939 940 941 942 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top