🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 998 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
149c1da7-9da8-4e3f-8d34-39ce464847b1 MEDIUM 6.1 The Latest Custom Post Type Updates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up … wordfence
147ad116-04fa-4dfa-9b96-26f361e19256 MEDIUM 6.1 The BabelZ – Google Translate Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in [version]. Th… wordfence
14667d93-4fba-4c50-8228-737ae91f2789
< 2.7
MEDIUM 6.1 The MailPoet Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wysija-key’ p… wordfence
1460dc44-dd64-4fd6-952b-1f5d4285bfa4
< 3.6.26
MEDIUM 6.1 The Ninja Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘data’ parameter in ver… wordfence
145a2ba1-67c1-4446-9269-cdbfdce77ef9 MEDIUM 6.1 The Cookie Scanner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
1454af30-319a-44b7-a83e-2d774cfbc8d1 MEDIUM 6.1 The PDF Image Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query… wordfence
1448f0d2-6b1f-45de-8e3a-81b9445cb16d MEDIUM 6.1 The Wizard Cloak plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
143e28b0-56cf-4d8d-9147-60a85a595290
< 10.3.9
MEDIUM 6.1 The WooCommerce and WP eMember Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … wordfence
1426bebe-d3c4-4f83-9b50-fae8c2373209
< 4.5.11.1
MEDIUM 6.1 The Duplicator Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
140f633c-c2e4-4b3c-befc-d870e06be970 MEDIUM 6.1 The Easy Custom Admin Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ paramet… wordfence
140c0d22-dc26-4100-a5c0-a2f8a6f98d97
< 4.2.9
MEDIUM 6.1 The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t… wordfence
140b1f50-7c04-4396-ab0a-098bd06c80a8
< 7.3.5
MEDIUM 6.1 The Zotpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'PHP_SELF' in versions up to, and … wordfence
1405e58a-0783-46f7-bbf0-9645777ed64e MEDIUM 6.1 The polka dots theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2… wordfence
14039d7d-bd5a-4c6b-96b0-46f86536e085
< 2.0.20
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Contact Bank plugin before 2.0.20 for WordPress allows remote attackers … wordfence
140262fc-23d0-4c30-9ce8-da9ccf2159df MEDIUM 6.1 The InLocation plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
13fb725f-cb16-49e3-b545-14266538c604
< 1.9
MEDIUM 6.1 The RokIntroScroller plugin for WordPress is vulnerable to Cross-Site Scripting via the 'src' parameter in the 'thumb.ph… wordfence
13e9deb0-73e1-44ea-820b-6cffe924b74b MEDIUM 6.1 The WP Colorful Tag Cloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
13e8f16b-b5a3-4be1-9557-e11cd9ffaea7
< 1.16
MEDIUM 6.1 The Enhanced Admin Plugin for WordPress is vulnerable to Cross-Site Scripting via the 'REQUEST_URI' variable in versions… wordfence
13e77d77-8f09-4fb9-8ff9-a8e66afe0393
< 2.1.6
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in services/diagnostics.php in the WordPress Social Login plugin 2.1.5 and earl… wordfence
13d53257-9dc7-4b7c-9472-72769099386c MEDIUM 6.1 The Custom Dashboard Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
13cfcc7a-8529-4bd5-9842-b9ad8eb5f4b3
< 1.8.22
MEDIUM 6.1 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
13cb5c62-34fb-4bbc-b42a-cc8a16d51258 MEDIUM 6.1 The Email Artillery (MASS EMAIL) plugin for WordPress is vulnerable to various Reflected Cross-Site Scripting via the 'c… wordfence
13ba9152-b9a0-4201-ba91-c41686b4d953
< 3.4.34
MEDIUM 6.1 In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable … wordfence
13a1e293-f539-4d19-8fe8-392c126fd1c4 MEDIUM 6.1 The intouch plugin for WordPress is vulnerable to Cross-Site Scripting via the 'intouch_failure' parameter in versions u… wordfence
1394b739-9d3a-4162-a7ca-3d20025eba52
< 1.4
MEDIUM 6.1 The GeoFlickr plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3… wordfence
← Prev 995 996 997 998 999 1000 1001 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top