🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1027 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d5a124b3-257b-4331-ac8f-eecd7a759127 MEDIUM 5.5 The WP-OliveCart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1… wordfence
d592b81d-48c7-4b48-948d-f2b98719fdfc
< 2.35
MEDIUM 5.5 The Minimal Coming Soon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_css’ and '… wordfence
d5744ed4-f150-48a6-9f5d-d49f9d4c8454 MEDIUM 5.5 The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could… wordfence
d542c1e8-7e9f-4687-8739-0ebcb865b998
< 2.0.0
MEDIUM 5.5 The Media Library Categories plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpmediacategor… wordfence
d4b4b5a0-b121-4ed2-b3ae-506f2950c7cf
< 3.9.1
MEDIUM 5.5 The Webling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.9.0 du… wordfence
d44f8891-cc24-4f6f-9032-3a4c632c6fb6
< 6.8.1
MEDIUM 5.5 The Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘SIRV_ACCOUNT_EMAIL’ parameter in… wordfence
d3b954e6-cf5d-4451-b770-777d116edd90
< 2.0.6
MEDIUM 5.5 The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the r… wordfence
d3a9a836-34c1-4ef3-9cde-c7ccb3163165 MEDIUM 5.5 The SEO 301 Meta WordPress plugin through 1.9.1 does not escape its Request and Destination settings, allowing high priv… wordfence
d2a77443-9fca-4686-be48-b3905a33c87f
< 1.1.4
MEDIUM 5.5 The TinyMCE Custom Styles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio… wordfence
d24b34d9-3aa3-46df-9000-eda8e416aa49
< 1.11.0
MEDIUM 5.5 The WP Bannerize Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includ… wordfence
d1d9166d-2715-4aa6-bf72-313708ac2910 MEDIUM 5.5 The Weather Layer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… wordfence
d1b4841b-c701-4915-9592-518e68179d20 MEDIUM 5.5 The Highlight Focus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
d0e2ae5c-685d-4cf0-91e2-2f8620b2eb6b MEDIUM 5.5 The Better Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several setting parameters in… wordfence
d0586453-76ec-4ec9-9965-780af7cb31ec
< 2.21.06.29
MEDIUM 5.5 The Async Javascript plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '&aj_gtmetrix_username=' … wordfence
d0237d64-40db-4e4e-be61-893217135ef7 MEDIUM 5.5 The AM-HiLi plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 due… wordfence
cfec9303-bdc5-4ba7-90dd-0c7559459d23
< 2.3.9.6
MEDIUM 5.5 The plugin Countdown, Coming Soon, Maintenance – Countdown & Clock for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
cfc59e3d-13c6-4051-8a1a-d109ea06b10b MEDIUM 5.5 The Opening Hours plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.3.0, vi… wordfence
cf9470c9-693b-4f36-91d9-26b2d488b377
< 4.7
MEDIUM 5.5 Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plu… wordfence
cf753fcf-9db0-4161-97e5-0f09c3452544
< 2.6.1
MEDIUM 5.5 The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Server-Side… wordfence
ce23efed-fe21-486a-ab3b-9ed0dd26a971
< 5.5.8
MEDIUM 5.5 The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti… wordfence
cd93da2b-a64d-45a0-8d6c-e2a93ef20e13
< 1.4.6
MEDIUM 5.5 The WordPress to Hootsuite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in v… wordfence
cd8c07cc-7fdd-4474-8be1-b08d857ae109
< 1.2.7
MEDIUM 5.5 The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the… wordfence
cd2a8e7b-6fca-49f3-ba6d-bdaa418f611a
< 2.25.1
MEDIUM 5.5 The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in … wordfence
ccf2bd2a-6041-49ca-8ff9-d8541b2d2b73
< 1.1.2
MEDIUM 5.5 The The Wordfence plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘goolytics_web_property_id… wordfence
cca16945-f230-4d0d-9f40-eabd5bf42e30
< 3.2.3
MEDIUM 5.5 The Easy Social Icons plugin for WordPress was vulnerable to admin+ stored Cross-Site Scripting due to missing sanitizat… wordfence
← Prev 1024 1025 1026 1027 1028 1029 1030 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top