🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1023 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f65cb1f6-e72e-4848-b72c-99b83e5401e8 MEDIUM 5.5 The Cookie Law Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
f63bf296-b34c-4f89-90eb-bba2a0461d57
< 2.0.5
MEDIUM 5.5 The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high … wordfence
f5e88393-c76b-49b6-a55c-06094e6f82d8
< 1.4.9
MEDIUM 5.5 The Login with Cognito plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in ver… wordfence
f5531449-c70f-488f-95ee-5208138968d1
< 2.1.4
MEDIUM 5.5 The Post SMTP Mailer/Email Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘input_tmp_di… wordfence
f4b1e7da-dbcd-4206-b908-4c814cde39d9
< 1.5.0
MEDIUM 5.5 The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, w… wordfence
f4a4e3ef-ee88-4175-8628-c5511c20bf23
< 3.7.17
MEDIUM 5.5 Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote a… wordfence
f477761d-3fad-4d35-8d41-d1710ec090f7
< 4.4.0
MEDIUM 5.5 The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,… wordfence
f3efd8d5-fa85-4910-8552-f38e92d7515e MEDIUM 5.5 The WP Parallax Content Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
f3e94710-66c5-4b96-a32b-525760ee4570
< 3.7.0
MEDIUM 5.5 The Sina Extension for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
f3d52baf-0f2b-4791-96ce-ec57502ed646
< 2.4
MEDIUM 5.5 The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege use… wordfence
f37fbbd8-234f-41bd-bb46-44de440f977c MEDIUM 5.5 The Beaf – Photo Comparison Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up… wordfence
f328b938-355d-426f-a9cf-646929a7c155
< 3.9.31
MEDIUM 5.5 The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… wordfence
f2ce4a14-5c56-4ca0-9deb-80cd609b71e6 MEDIUM 5.5 The WP Config File Editor WordPress plugin through 1.7.1 was affected by an Authenticated Stored Cross-Site Scripting (X… wordfence
f27853e0-1785-4670-a7b2-f72c19f4a6ac MEDIUM 5.5 The WP Clictracker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
f2675177-8b85-4fb8-ba10-ae02cb5c6c72
< 3.2.4
MEDIUM 5.5 The Booking calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up… wordfence
f25b2a4b-d863-4f24-ae67-4c8e41602c6f
< 3.1.42
MEDIUM 5.5 The WP Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
f2329a5d-0649-498e-a18c-a17de7b30df4
< 6.5.2
MEDIUM 5.5 The Modern Events Calendar Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
f21c70aa-22be-456d-93bb-f478b70deaef
< 3.7.21
MEDIUM 5.5 In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an inv… wordfence
f2126761-cbff-4d46-a6df-4566d15216d7
< 5.1.0
MEDIUM 5.5 The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.6… wordfence
f1666371-9401-4b62-b44e-abc7fb4c6138
< 1.4.0
MEDIUM 5.5 Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) in Mark Daniels Night Mode plugin <= 1.0.0 on Word… wordfence
f10fdf31-6941-4d41-8c15-90ed61addc2f
< 3.7.17
MEDIUM 5.5 Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in W… wordfence
f00cdef3-d733-4e85-8099-204ef76096b4
< 9.8.5
MEDIUM 5.5 The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values th… wordfence
f002e61b-7395-4ba7-8695-da17cfc001cc
< 6.0.6
MEDIUM 5.5 The WP Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6… wordfence
eff9fcce-01b2-4698-a2c2-ee5991bfd963
< 1.8.2
MEDIUM 5.5 The Patreon WordPress plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.8.1… wordfence
ee95976d-6454-466b-96b3-7c33ccc03d41 MEDIUM 5.5 The Simple Real Estate Pack WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which coul… wordfence
← Prev 1020 1021 1022 1023 1024 1025 1026 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top