🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1025 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e758b973-dc2f-4bcf-9846-56ddd73f38db MEDIUM 5.5 The Backup and Restore plugin – WordPress plugin for WordPress is vulnerable to Arbitrary File Deletion via the 'folde… wordfence
e7535b43-dcf0-4d00-833a-d9d86b2520d5
< 0.8.1
MEDIUM 5.5 The Anthologize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_title’, 'post_status… wordfence
e72e35de-caeb-4ecb-8d13-72fd2df4dd69
< 2.2
MEDIUM 5.5 The HAL WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitizat… wordfence
e72b7e6b-c8ad-44be-b23d-69e8a27670ea
< 3.8.4
MEDIUM 5.5 The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Server-Side… wordfence
e724394d-97aa-42e4-b36e-6e49bfefa2f6
< 3.0.4
MEDIUM 5.5 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the progress bar … wordfence
e67422cc-c1ad-40b6-abae-23447e2ff491
< 5.10.4
MEDIUM 5.5 The Customer Service Software & Support Ticket System WordPress plugin before 5.10.4 does not sanitize or escape form fi… wordfence
e659cc27-ae01-4d7b-a6f4-9fcb2aeb1b57 MEDIUM 5.5 The Qe SEO Handyman plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to ins… wordfence
e6001516-3d3c-48a9-92ae-a1d249d58cec
< 4.0
MEDIUM 5.5 The Kwayy HTML Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parame… wordfence
e57631c2-ad6c-4c8c-985e-948285058567
< 1.1.19
MEDIUM 5.5 An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi… wordfence
e5726719-0dfc-4e06-b676-006302b2b38b MEDIUM 5.5 The AI Content Writer, Autoblogging, Youtube Subtitle to Article – SEO Help plugin for WordPress is vulnerable to Serv… wordfence
e570a66a-14f4-4ce9-b820-c54d09dd051d
< 3.0.14
MEDIUM 5.5 The Apptivo Business Site CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter… wordfence
e511497d-eb79-4c8c-8b2d-c6ad43d2a3ec MEDIUM 5.5 The Login Redirect plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
e4b8947a-6c87-4430-b62d-494863e18fdb
< 1.1.19
MEDIUM 5.5 An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi… wordfence
e481c916-0789-4b04-a7f8-dbde554a5e8c
< 2.5.0
MEDIUM 5.5 The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high p… wordfence
e42841dc-157f-45eb-8959-249326d50650
< 2.4.2
MEDIUM 5.5 The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or es… wordfence
e3dd3b5e-b0df-45b0-b42d-eaea765f3193 MEDIUM 5.5 The ImageInject plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in version… wordfence
e3891928-3780-426b-ae9c-e57b05ab3718
< 1.1.19
MEDIUM 5.5 An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi… wordfence
e36e5099-c5ff-4794-b7df-25d8eab27bac
< 1.18
MEDIUM 5.5 The Metricool plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in v… wordfence
e33fb34e-0ea3-4bac-9134-afc8bb830b48
< 6.2
MEDIUM 5.5 The Hand Talk plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.1 du… wordfence
e20fe2b7-4396-465e-be41-d4e8a069bb74 MEDIUM 5.5 The Image/Banner Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Widget title parameter… wordfence
e1dcdc7f-ae52-4c76-90db-ea136656bb0b
< 1.6.3
MEDIUM 5.5 The WP24 Domain Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versio… wordfence
e15ca55b-b8e4-4f65-87a4-e13209cfea78 MEDIUM 5.5 The Add User Role plugin for WordPress is vulnerable to Stored Cross-Site Scripting via in versions up to, and including… wordfence
e13a1d8c-efcf-4bb5-8c39-33b06ae65d1a
< 2.5
MEDIUM 5.5 The WP Modal Popup with Cookie Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… wordfence
e08cd1b6-3faf-4650-9606-3724b6a52df5
< 8.0.0
MEDIUM 5.5 The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and … wordfence
df534aba-242a-45c2-9d1c-6a08b58f8ee7
< 1.5.9
MEDIUM 5.5 The Responsive Vertical Icon Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i… wordfence
← Prev 1022 1023 1024 1025 1026 1027 1028 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top