🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 991 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
14f5a5c5-1c06-49fb-accd-0cbe992b9d3a MEDIUM 6.1 The Search order by product SKU for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in … wordfence
14f030bd-8d8d-4152-817d-d72c9b7a0152 MEDIUM 6.1 The VK Poster Group plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘vkp_repost’ parame… wordfence
14ee389b-8f98-4991-9a61-9da596013fea
< 0.2
MEDIUM 6.1 The Social Login by BestWebSoft plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includ… wordfence
14da4735-894e-408a-864b-cdc76feacde9
< 4.4.5
MEDIUM 6.1 The Video Conferencing with Zoom plugin for WordPress is vulnerable to Open Redirect in all versions up to, and includin… wordfence
14c3b53c-ba98-4e93-ba65-6da11816d7a6 MEDIUM 6.1 The MP-Ukagaka plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
14c24bff-91a1-402a-a9d1-a1a7800db62f MEDIUM 6.1 The Multi Item Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
14bf2f2e-4607-4817-ab8c-d986315964bc MEDIUM 6.1 The UberSlider PerpetuumMobile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
14aff362-2f49-460e-94db-1e0573c91c88 MEDIUM 6.1 The Google Font Fix plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
149c1da7-9da8-4e3f-8d34-39ce464847b1 MEDIUM 6.1 The Latest Custom Post Type Updates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up … wordfence
147ad116-04fa-4dfa-9b96-26f361e19256 MEDIUM 6.1 The BabelZ – Google Translate Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in [version]. Th… wordfence
14667d93-4fba-4c50-8228-737ae91f2789
< 2.7
MEDIUM 6.1 The MailPoet Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wysija-key’ p… wordfence
1460dc44-dd64-4fd6-952b-1f5d4285bfa4
< 3.6.26
MEDIUM 6.1 The Ninja Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘data’ parameter in ver… wordfence
145a2ba1-67c1-4446-9269-cdbfdce77ef9 MEDIUM 6.1 The Cookie Scanner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
1454af30-319a-44b7-a83e-2d774cfbc8d1 MEDIUM 6.1 The PDF Image Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query… wordfence
1448f0d2-6b1f-45de-8e3a-81b9445cb16d MEDIUM 6.1 The Wizard Cloak plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
143e28b0-56cf-4d8d-9147-60a85a595290
< 10.3.9
MEDIUM 6.1 The WooCommerce and WP eMember Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … wordfence
1426bebe-d3c4-4f83-9b50-fae8c2373209
< 4.5.11.1
MEDIUM 6.1 The Duplicator Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
140f633c-c2e4-4b3c-befc-d870e06be970 MEDIUM 6.1 The Easy Custom Admin Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ paramet… wordfence
140c0d22-dc26-4100-a5c0-a2f8a6f98d97
< 4.2.9
MEDIUM 6.1 The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t… wordfence
140b1f50-7c04-4396-ab0a-098bd06c80a8
< 7.3.5
MEDIUM 6.1 The Zotpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'PHP_SELF' in versions up to, and … wordfence
1405e58a-0783-46f7-bbf0-9645777ed64e MEDIUM 6.1 The polka dots theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2… wordfence
14039d7d-bd5a-4c6b-96b0-46f86536e085
< 2.0.20
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Contact Bank plugin before 2.0.20 for WordPress allows remote attackers … wordfence
140262fc-23d0-4c30-9ce8-da9ccf2159df MEDIUM 6.1 The InLocation plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
13fb725f-cb16-49e3-b545-14266538c604
< 1.9
MEDIUM 6.1 The RokIntroScroller plugin for WordPress is vulnerable to Cross-Site Scripting via the 'src' parameter in the 'thumb.ph… wordfence
13e9deb0-73e1-44ea-820b-6cffe924b74b MEDIUM 6.1 The WP Colorful Tag Cloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
← Prev 988 989 990 991 992 993 994 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top