🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1022 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fe44fe7f-0ccf-4297-a9a7-107695abfe13
< 2.3.1
MEDIUM 5.5 The Uji Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in version… wordfence
fe31346e-a06e-4b4d-b13c-7a98dca53274
< 2.11.17
MEDIUM 5.5 The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up… wordfence
fde163fa-2dbf-43bc-8edc-cbbab2a35bd0 MEDIUM 5.5 The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them bac… wordfence
fdd14863-5498-4598-8b22-8e5a607869e4
< 1.3.11
MEDIUM 5.5 Video Gallery – YouTube Playlist, Channel Gallery by YotuWP is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
fd3298dd-af80-481e-8d20-d33e7bb9bb85 MEDIUM 5.5 The KJM Admin Notices WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation… wordfence
fd235256-e48c-4f1b-a51b-25669b560c77 MEDIUM 5.5 The gee Search Plus, improved WordPress search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm… wordfence
fc3c22a2-b766-419c-a481-48e6a73b084c
< 5.1.3.4
MEDIUM 5.5 The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions]… wordfence
fbee3720-6ab9-4470-b2d2-09824db8de4d
< 1.3.2
MEDIUM 5.5 The Where Did You Hear About Us Checkout Field for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
fbb9b4c8-18b6-4215-a7ee-c5a49977aec7 MEDIUM 5.5 The Epeken All Kurir plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
fb87726f-868d-4b2e-b818-d303e695c69c
< 4.59.4
MEDIUM 5.5 The amr users WordPress plugin before 4.59.4 does not sanitise and escape some of its settings, which could allow high p… wordfence
fb2f463f-2c99-4a6c-92b9-45fb2192381d MEDIUM 5.5 The Video Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in vers… wordfence
fa3d4308-0e34-4749-a7da-935d416ad2d0
< 1.9
MEDIUM 5.5 The Feedweb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_post_id' parameter in versions… wordfence
fa181ff8-5324-4782-ad45-4a701ac63b8c
< 1.7.6
MEDIUM 5.5 The CM Ad Changer plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1… wordfence
fa139703-e83e-4a19-a801-464b72a2acc4
< 3.7.40
MEDIUM 5.5 WordPress Core is vulnerable to Stored Cross-Site Scripting, exploitable during comment editing, in versions up to 6.0.3… wordfence
fa05ad02-8625-4bf9-983e-548fbb7634f3 MEDIUM 5.5 The Qe SEO Handyman plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to ins… wordfence
f9ad3a88-fcfd-45c5-a23d-ca544cad3ab2 MEDIUM 5.5 The Content Repeater plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
f9478d3e-d2f9-458b-a6ca-3baef21db60e
< 2.1.0
MEDIUM 5.5 The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘license’ parameter used in… wordfence
f8e6bfd4-9003-4ac6-96a1-0c7024b2a800
< 7.4.1
MEDIUM 5.5 The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versions… wordfence
f8d093ae-e0b1-49c2-a492-e01f2e954ddb
< 1.30.3
MEDIUM 5.5 The MPL-Publisher WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and… wordfence
f7cb3540-ffdb-4b4c-a518-4ca8232ab53f
< 9.1.3
MEDIUM 5.5 The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Check for online users ever… wordfence
f7c9fb37-bda0-4a5d-811e-1f422c58bb06 MEDIUM 5.5 The WP Featured Content Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
f787cad3-cf99-413a-952f-082fae973bef
< 3.1.1
MEDIUM 5.5 The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the critical css settings rules in… wordfence
f6e47659-90d9-4990-a19d-3954d65417df MEDIUM 5.5 The Job Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and s… wordfence
f6cba253-dfb0-485d-8b81-8e3bbaec8441
< 1.1.9
MEDIUM 5.5 The RSS Feed Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1… wordfence
f6c4ec70-22b5-49e1-a00b-5b29aab5fc91
< 1.8.5
MEDIUM 5.5 The Split Test For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
← Prev 1019 1020 1021 1022 1023 1024 1025 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top