🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 974 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
26c75a0a-8590-4ac7-814e-29e0c2d0822e MEDIUM 6.1 The Custom Post Type and Taxonomy GUI Manager for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
26ab8551-ec47-40ab-8beb-2625cc20e735 MEDIUM 6.1 The Homey theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.4.5 du… wordfence
26a2a20e-f200-4cb1-aa15-db12c86dd351 MEDIUM 6.1 The FS Product Inquiry plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… wordfence
269e3b47-3775-41c1-9ed1-70c4177cbe8b
< 0.52
MEDIUM 6.1 The WP Log Action plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'log_time_start' and 'log… wordfence
2694747e-9423-475c-a3a8-d0afed9758ee MEDIUM 6.1 The MediCenter - Health Medical Clinic WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripti… wordfence
2678d2c6-055e-462e-99da-bdc81bcc3662
< 2.3.0
MEDIUM 6.1 The Affiliate Power – Sales Tracking for Affiliate Marketers plugin for WordPress is vulnerable to Reflected Cross-Sit… wordfence
26766830-c772-46a3-a045-7bfbb530b50a
< 1.5.13
MEDIUM 6.1 The Gallery Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘delete’ parameter … wordfence
26753b92-3ec5-4b65-8fc7-2d6488f12974
< 3.7.14
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5… wordfence
2668ad2e-d7ae-47f2-90b1-5f9c31c8fee2 MEDIUM 6.1 Multiple themes for WordPress by Themify Themes are vulnerable to Reflected Cross-Site Scripting in various versions due… wordfence
26624f19-c943-417a-abb2-c05646b192cf MEDIUM 6.1 The Parsian Bank Gateway for Woocommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via and parame… wordfence
262b5326-a5e6-4063-a345-59dedd14c3c2 MEDIUM 6.1 The Viable blog theme for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.4 due to… wordfence
2628b02e-5685-4e25-a786-4542ecbe874a
< 2.0.0
MEDIUM 6.1 The Gallery – Image and Video Gallery with Thumbnails plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
2627ac2b-25a8-480d-ac83-ee0ca323b3a1
< 1.0.18
MEDIUM 6.1 The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … wordfence
261b5905-9194-40d3-99cb-1c7a832218dc
< 0.6.0.7
MEDIUM 6.1 The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before… wordfence
2614ca26-6efc-49f5-8cee-5b078721acc1
< 1.3.8.1
MEDIUM 6.1 The JetBlocks for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
2608f894-88ed-4f34-a382-8eab7eaab2e7
< 7.5.4
MEDIUM 6.1 The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter befor… wordfence
25e4ed00-a9f2-402f-8a46-3cb911ab5497
< 1.5.3
MEDIUM 6.1 The Loan Comparison plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a shortcode, in versions up… wordfence
25dfa483-26c6-43d1-9a24-9ea245b54f4c MEDIUM 6.1 The Like DisLike Voting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF… wordfence
25deb040-1338-40bd-b83e-be3a302e635c MEDIUM 6.1 The While Loading plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
25de953d-e8c4-4ac7-ae6c-d8262bb083cd
< 5.3.3
MEDIUM 6.1 The Slimstat Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
25cde35e-ba76-4651-8828-71ddd4c8a164
< 12
MEDIUM 6.1 The Newspaper theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an AJAX action in versions up to, … wordfence
25c44a00-da56-41f8-bd4f-c15bede6da58
< 4.8.3
MEDIUM 6.1 The email-users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in ver… wordfence
25ba4be3-0bcd-41ff-8a7a-fd6ae848afb8 MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in xencarousel-admin.js.php in the XEN Carousel plugin 0.12.2 and ea… wordfence
25b32ad8-db0f-4391-a644-2759e35824ff MEDIUM 6.1 The Naver Syndication V2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
25b13322-d305-45db-8ac7-20762398dc21
< 2.4.6
MEDIUM 6.1 The Update Image Tag Alt Attribute plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'posts_index… wordfence
← Prev 971 972 973 974 975 976 977 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top