πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 980 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
205d639c-6fc9-425c-b7ec-89217e02a028 MEDIUM 6.1 The Database Peek WordPress plugin through 1.2 does not sanitize and escape the 'match' parameter before outputting it b… wordfence
20590ca1-78f1-47d4-be6e-9378d850103f MEDIUM 6.1 The Paloma Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
2052278d-f1df-4a31-8688-11c7c8d20e07
< 2.0.9.11
MEDIUM 6.1 The Groundhogg plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.… wordfence
202c22f1-48ce-4724-be5f-dece2a6f9adb MEDIUM 6.1 The Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 21.07.… wordfence
202a8724-14da-4edb-870e-2fee205b1d53
< 1.5.2
MEDIUM 6.1 The "Vision Interactive For WordPress" plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜p… wordfence
2016224c-a9f9-4161-885f-310830f48038
< 1.4
MEDIUM 6.1 The WP Timed Popout plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting via … wordfence
2012090d-fd96-4609-aef1-0e3ec5dd2e38
< 1.0.7
MEDIUM 6.1 The Pagination by BestWebSoft plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includin… wordfence
200b579a-0287-4e2a-afb2-3b77b94dad25
< 4.9.14
MEDIUM 6.1 The Spiffy Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
2009db96-e0e6-4a61-948a-4e1cdab2a6f4 MEDIUM 6.1 The Podamibe Twilio Private Call plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… wordfence
20087364-11d6-4346-8b80-c3a3739598f9 MEDIUM 6.1 The Pootle button plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
2006dbb8-2aa8-4890-b6ce-18257c64b970
< 1.5.6
MEDIUM 6.1 The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
2002ac51-79c1-4cee-92ff-c58927f27cce MEDIUM 6.1 The Simple Email Subscriber plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
2001d14c-2738-4d34-b465-0a76c2f772e6
< 3.21.3
MEDIUM 6.1 The Elementor Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
1ff97ee8-9732-4d26-b5e8-b744730e9c5a MEDIUM 6.1 The Easy Flashcards plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
1feddb10-5790-45d9-99e8-401c2f60bdf4 MEDIUM 6.1 The Czater.pl – live chat i telefon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
1fe082a7-3d36-48b4-b81f-1e65e5ea430d
< 6.5.3
MEDIUM 6.1 The Intro Tour Tutorial DeepPresentation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't… wordfence
1fdc68b3-271c-43e1-a785-195f68d790f7
< 5.0.22
MEDIUM 6.1 The LTL Freight Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
1fdbcfc7-1db6-4379-98fb-af2e1a7a7aaf
< 12.8.6
MEDIUM 6.1 The Real Estate Manager Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
1fd5d806-916e-4ae6-a8a8-2b72a441a3fe MEDIUM 6.1 The MultiMailer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
1fd5c090-9a05-4487-aa7e-97dc091e7f18 MEDIUM 6.1 The ComparePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
1fd566e5-90f5-4f67-8998-85cabea33e93
< 8.2.5
MEDIUM 6.1 The Soledad plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜id’ parameter among other… wordfence
1fbd47c2-e1c0-4b72-a211-d143ffcc9d88 MEDIUM 6.1 The Live Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
1fa87357-09c0-4e99-8ceb-41a7987c4a57
< 2.1.0
MEDIUM 6.1 The Open RDW kenteken voertuiginformatie plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'o… wordfence
1f82845c-55db-491a-90c1-326884abb5d6
< 2.0.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in resize.php in the WebEngage plugin before 2.0.1 for WordPress allows remote … wordfence
1f7f4308-6f6c-4eec-9ebc-9c7709c14662 MEDIUM 6.1 The Kv Compose Email From Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions… wordfence
← Prev 977 978 979 980 981 982 983 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top