🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1024 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ee5737b3-de32-4b5c-a9df-7909ad32ec93
< 2.1.0
MEDIUM 5.5 The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pages’ parameter used in t… wordfence
edf0760c-356a-4c55-9ccc-9f086dae12b6
< 2.8.7
MEDIUM 5.5 The Casso plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versions up to,… wordfence
eda18b47-1c23-4ef5-9628-d6b5842bca04
< 3.43
MEDIUM 5.5 The WPUpper Share Buttons plugin for WordPress is vulnerable to Authenticated (Admin+) Stored Cross-Site Scripting via t… wordfence
ecf1ce11-58cd-459c-ab9e-6ac40535fabd MEDIUM 5.5 The WP Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in versions up… wordfence
ecde34f7-4624-4361-8d95-56fd4b08b476
< 2.35
MEDIUM 5.5 The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the c… wordfence
ec6f2c0d-4d92-4982-995d-5d8a9866b888
< 1.1.1
MEDIUM 5.5 Stored cross-site scripting (XSS) in form field in robust.systems product Custom Global Variables v 1.0.5 allows a remot… wordfence
ebe215c6-b328-49b7-aed7-e164e1c5f0d0
< 1.5.8
MEDIUM 5.5 The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputti… wordfence
eb38027a-1ee2-452a-b9b8-c1b47edbd08f MEDIUM 5.5 The WP Header Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
eb299b03-a176-43b3-beca-944c32a5af49
< 1.2.2
MEDIUM 5.5 The BP Group Documents plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
eb290fa8-206e-44c6-9107-8a896225664c MEDIUM 5.5 The Job Board Vanila WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation … wordfence
ea01e11e-31b5-4cd9-8fab-3693e47f705a
< 1.4.3
MEDIUM 5.5 The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
e9ee4f4e-5098-406c-b712-a2484180a07d
< 1.11.20
MEDIUM 5.5 The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘youtube_api_key’ … wordfence
e9ae8fa3-206c-496d-9902-c6468964b717
< 1.0.64
MEDIUM 5.5 The WordPress Advanced Ticket System, Elite Support Helpdesk WordPress plugin before 1.0.64 does not sanitize or escape … wordfence
e98ed932-4e4c-4127-ae72-500e2a34f371
< 3.6.5
MEDIUM 5.5 The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in v… wordfence
e96e94f8-f61c-4458-9ede-53bab30502b6
< 6.9.21
MEDIUM 5.5 The Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More plugin for WordPress is vu… wordfence
e9222c74-7f4f-4d20-8c1e-03be125709ff
< 1.4.9
MEDIUM 5.5 The VDZ Google Analytics or Google Tag Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sev… wordfence
e91e6101-bd30-4cf1-9a39-23218c3bff6f
< 6.5.4
MEDIUM 5.5 The Newsletter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.5.3 by the use of… wordfence
e9012824-7221-4b93-a5fb-65caf7994e92
< 5.3.4
MEDIUM 5.5 Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3).… wordfence
e8d1c4ab-1207-4414-9351-3ef2a3cd131b
< 1.86.1
MEDIUM 5.5 The WP-PostRatings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘postratings_image’ par… wordfence
e8ac3187-b065-434e-9051-d13330dd3da5
< 2.8
MEDIUM 5.5 The Duplicate Page and Post plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and inc… wordfence
e8a6e9b7-5e74-4a45-9e6e-5781bf2a4a07
< 2.3.44
MEDIUM 5.5 The Slide Anything WordPress plugin before 2.3.44 does not sanitize and escape sliders' description, which could allow h… wordfence
e87ea6b5-4288-4ebb-8a29-e0a179e6b584
< 1.7
MEDIUM 5.5 The Animated Number Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
e86ab1ea-5b3c-4a14-9de1-3bae14f587c5 MEDIUM 5.5 The Social Media Flying Icons | Floating Social Media Icon plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
e85df0dc-d3da-4503-9249-939bb36f18ab
< 1.0.99
MEDIUM 5.5 The plugin Coming Soon & Maintenance Mode by Colorlib for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
e8270ef0-7c98-4bb1-af83-bdcc2c7867ab MEDIUM 5.5 The Content Staging WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation a… wordfence
← Prev 1021 1022 1023 1024 1025 1026 1027 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top