πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 966 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2f79778c-c11a-4d98-bc26-8113c3fef630
< 2.1.2
MEDIUM 6.1 The Transporters.io plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
2f715a80-ec70-4f1e-8ec9-c6f70173e5d7
< 4.3.21
MEDIUM 6.1 The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting … wordfence
2f640ae4-b53b-4644-9c47-0d360057c01a MEDIUM 6.1 The Events Planner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
2f621cfa-d02e-4414-bb1d-6e23da3c92b9
< 1.4.4
MEDIUM 6.1 The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all v… wordfence
2f5d874a-d70e-4d3f-a9aa-d24707a3f7f4
< 2.2.34
MEDIUM 6.1 The WooCommerce Bulk Stock Management plugin plugin for WordPress is vulnerable to Cross-Site Scripting in versions up t… wordfence
2f58d7e9-3764-4478-82ab-6d21990cd573 MEDIUM 6.1 The Post Connector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
2f4a0b8d-0f3b-4ab1-929e-071b45781ca7
< 1.8.3.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in wassup.php in the WassUp plugin before 1.8.3.1 for WordPress allows remote a… wordfence
2f438626-2984-49b8-878a-291887e81375
< 3.1
MEDIUM 6.1 The Image Wall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
2f40b4fb-4e90-4a5a-9667-20e4087abe00
< 9.2.07.002
MEDIUM 6.1 The Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
2f383a56-21e3-4f06-b4d4-47a269007cdc
< 1.6.1
MEDIUM 6.1 The Subaccounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a… wordfence
2f34854a-5ca1-48a3-81d5-80f80f3a85fc MEDIUM 6.1 The WP Forms Puzzle Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
2f340cfe-0829-444a-a67d-867ac8650b21 MEDIUM 6.1 The kento-post-view-counter plugin through 2.8 for WordPress has stored XSS via kento_pvc_numbers_lang, kento_pvc_today_… wordfence
2f280d50-196b-43a9-83f8-713d84ea1a00
< 15.8
MEDIUM 6.1 The WP GoToWebinar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
2f257c92-1529-49c8-a140-567ba5c36d04 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in Peter's Random Anti-Spam Image 1.0.6 and earlier plugin for WordPress allows… wordfence
2f14b0b9-6ccd-4f53-b015-e8537127b909
< 1.1.4.3
MEDIUM 6.1 The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulne… wordfence
2f0e7f9f-cc9b-4e90-a768-776c927b6d83 MEDIUM 6.1 The TRUSTist REVIEWer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
2f08961b-8da2-40bf-b197-aea76c4e79f9
< 1.2.04.25
MEDIUM 6.1 The EZ Related Posts Footer Links and Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
2efeffa2-b21a-4aa1-93b0-51c775758ab1 MEDIUM 6.1 The Page Builder by AZEXO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
2ef6d5f4-fc29-4b9f-b3cc-834eff37b085 MEDIUM 6.1 The Mobile Smart plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
2ee837fd-a41e-44f2-81e8-258a7d8547bd MEDIUM 6.1 The TheAgency theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and outpu… wordfence
2ee3d536-6d7b-41dc-9d63-52b9b4facf73
< 1.3.3
MEDIUM 6.1 The Easy Digital Downloads (EDD) Digital Store theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.… wordfence
2ec35484-8561-4a8c-bf67-0a880f915fb1 MEDIUM 6.1 The Social Share With Floating Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o… wordfence
2eb70d40-b1c1-456e-9207-66b6e91969eb MEDIUM 6.1 The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up… wordfence
2eb65c25-9400-4c5a-a4b2-b72628725500 MEDIUM 6.1 The Starred Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the PHP_SELF variable in all… wordfence
2e9291e8-b4f5-4fd1-aded-4690f82f6905
< 3.3.2
MEDIUM 6.1 wordfence
← Prev 963 964 965 966 967 968 969 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top