🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1026 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
de9f3b83-4575-4566-9731-0af9107c7c30 MEDIUM 5.5 The 0mk Shortener for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and i… wordfence
de568a71-f51d-4948-839c-48e51d165a64 MEDIUM 5.5 The Simple Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions u… wordfence
de0fbcf0-64c6-4b33-8a9d-9c9c5d826a4d
< 5.4.3
MEDIUM 5.5 The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings in versions u… wordfence
ddbc76d0-23cd-4f49-939b-b8f19ff55d5c MEDIUM 5.5 The Page Security & Membership WordPress plugin through 1.5.15 does not sanitise and escape some of its settings, which … wordfence
dd8f355b-736b-442a-917e-9fa603abb853 MEDIUM 5.5 The AB Press Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
dd1b6b89-6c3c-4956-aa99-798ce186eb97
< 2.9.1
MEDIUM 5.5 The Beautiful Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple param… wordfence
dd163f14-c638-4185-8e14-f3a03312ee42
< 1.2.1
MEDIUM 5.5 The Advanced Comment Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the settings form in ve… wordfence
dc783305-1cd0-4ec1-b4e2-57afeeec8034
< 1.5.14
MEDIUM 5.5 The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, whic… wordfence
dc5050dc-39de-4544-bf51-0927b2972d34
< 9.1
MEDIUM 5.5 The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the 'add_acl_comment' param… wordfence
dc37397e-cd23-4ffd-9771-316d7f9ff9fa MEDIUM 5.5 The Twitter Bootstrap Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in… wordfence
dc049cab-6793-4656-9b17-8ca64c566c4c MEDIUM 5.5 The Modal Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
dc036236-4d20-4926-9837-52973f632248
< 1.7
MEDIUM 5.5 The BP Email Assign Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
dbc6ad3f-698e-4dfd-bbba-086f94831bba
< 4.9.8
MEDIUM 5.5 The Import any XML or CSV File to WordPress PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SV… wordfence
da4f5af6-61b2-4983-9096-66f6ff7fc060 MEDIUM 5.5 The Analytics for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in vers… wordfence
da15614b-6619-4ccb-93eb-12923910fb41
< 1.2.8
MEDIUM 5.5 The click-to-top plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Type scroll text' field in v… wordfence
d99d7a26-3645-4ff5-8c48-17b6fa77a228
< 2.4.2
MEDIUM 5.5 The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sanitize_… wordfence
d979f899-8cdc-4230-b1b5-865c025dc86a
< 3.23.0
MEDIUM 5.5 The My YouTube Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in … wordfence
d95d8ca6-a36e-4d95-bce3-ead237dac938
< 2.2.8
MEDIUM 5.5 The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged … wordfence
d8c0cd48-b27c-4bc1-9e5f-d918448290fb
< 3.10
MEDIUM 5.5 The Trade Runner plugin for WordPress is vulnerable to authenticated Stored Cross-Site Scripting in versions up to, and… wordfence
d8b47395-6d04-4ecc-9ae5-081aabe30d31
< 2.6.0
MEDIUM 5.5 The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to Server-Side Request Fo… wordfence
d7bf5f3c-9577-4824-a8ae-e13827fa5166 MEDIUM 5.5 Cross-Site Scripting (XSS) vulnerability in Muneeb's WP Slider Plugin <= 1.4.5. wordfence
d7778de0-591e-469a-acb2-5a66490a4690
< 4.8.0
MEDIUM 5.5 The Mihdan: No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters i… wordfence
d73fd485-cb59-42eb-9426-9b89299bb6bc MEDIUM 5.5 The Thank Me Later WordPress plugin through 3.3.4 does not sanitise and escape the Message Subject field before outputti… wordfence
d63bc735-b2ba-4be6-bd1c-f904ef860f5e
< 2.7
MEDIUM 5.5 The Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6… wordfence
d5df75f8-1250-4b79-a796-9146d3037bec
< 3.86
MEDIUM 5.5 The Under Construction plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.85… wordfence
← Prev 1023 1024 1025 1026 1027 1028 1029 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top