ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 982 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1e2b9845-53d6-438d-87cc-8b6badae007d MEDIUM 6.1 The Yahoo! WebPlayer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
1e1d2883-59d4-49c8-9a02-cf61c78df7a7 MEDIUM 6.1 The Internal Link Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
1e1b4c96-8fe5-4e89-afb5-5e5de97bba52 MEDIUM 6.1 The In Stock Mailer for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up … wordfence
1e12494c-e777-4ee1-be70-7469141f968f MEDIUM 6.1 The UpDownUpDown plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
1e07593a-3d12-4afe-a21e-fc85bd6d4bef MEDIUM 6.1 The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in vers… wordfence
1e012c3c-b81a-4fb8-b72f-6d2898734535 MEDIUM 6.1 The WordPress-to-candidate for Salesforce CRM plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in al… wordfence
1df84722-8036-4c9c-b9f7-b49852fad4cd MEDIUM 6.1 The Callback Request plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
1de69b7e-944a-4d89-a7de-2fae5ab83171
< 1.8.1
MEDIUM 6.1 The Raygun4WP plugin 1.8.0 for WordPress is vulnerable to a reflected XSS in sendtesterror.php (backurl parameter). wordfence
1de3e564-c5a8-424c-9e94-b15956b9c2af MEDIUM 6.1 The WP Intro.JS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
1ddb9fc8-bed4-42ff-9664-6ea8fb136ec0
< 1.55.3
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in comments/videowhisper2/r_logout.php in the Video Comments Webcam Recorder pl… wordfence
1dd2ac9e-210b-4d8d-a048-df0df6b10c13 MEDIUM 6.1 The Pro Rank Tracker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
1dcfbdad-a70b-4244-b89d-ddd13d7397a0
< 0.9.52
MEDIUM 6.1 The codoc plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 0.9… wordfence
1dcbd3b3-33b7-47f1-bd04-5f60587ae184 MEDIUM 6.1 The EU DSGVO Helper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
1dc7341f-35ee-45ab-a243-d450cc870014
< 2.1.1
MEDIUM 6.1 The Property Hive plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ph_message' parameter in… wordfence
1dc733ec-6cc8-40fc-b4c4-1fad4bcd9f21
< 5.2.6
MEDIUM 6.1 The Email Tracker – Email Tracking Plugin to track Emails for Open and Email Links Click (Compatible with WooCommerce)… wordfence
1dba61bb-2d26-483e-835f-c3841f07efe6
< 23.1.3
MEDIUM 6.1 The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Soc… wordfence
1d9e80da-4cc6-425c-892f-1ff34b07583f
< 2.2.2
MEDIUM 6.1 The Preview E-mails for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions… wordfence
1d95e90d-f8f4-4e9f-b8c9-cfd89516679e MEDIUM 6.1 The moseter theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3.1 … wordfence
1d8c1290-8367-4378-8171-8a60bdb2f146
< 1.8
MEDIUM 6.1 The Video Embedder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
1d73f773-f084-40da-b18f-8b30b0d0c08a
< 0.98
MEDIUM 6.1 The S3 Video, EasySqueezePage, External "Video for Everybody", Videopack, and 1player plugins for WordPress are vulnerab… wordfence
1d6faee0-716e-4aa9-a841-5231c7aaff21
< 1.2.0
MEDIUM 6.1 Easy EU Value Added (VAT) Taxes Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and r… wordfence
1d68ea19-9592-483a-a5fd-635819f9b863 MEDIUM 6.1 The Easy Custom JS And CSS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ param… wordfence
1d633f71-3b2b-4fe3-80f1-4c2dcc86313c MEDIUM 6.1 The WooCommerce HSS Extension for Streaming Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v… wordfence
1d61ab0b-7559-4ba0-bbf7-cbc40e5c188b MEDIUM 6.1 The Photo Video Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
1d45bd32-d693-40e6-9b30-9e0b91eb4660
< 8.7.6
MEDIUM 6.1 The WooCommerce Composite Products plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up t… wordfence
← Prev 979 980 981 982 983 984 985 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top