🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1029 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c3c961eb-0174-4aa3-a117-7f72998eefbb
< 2.2
MEDIUM 5.5 An issue was discovered in the read-and-understood plugin 2.1 for WordPress. XSS exists via the wp-admin/options-general… wordfence
c394295f-d1b5-48be-978f-f15a6b56e40f
< 1.7.0
MEDIUM 5.5 The WP Server Health Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘API Pro Key’ p… wordfence
c34b21da-6c35-4eec-826b-47dc46575971
< 4.1.11
MEDIUM 5.5 The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… wordfence
c29cb99f-72e9-4178-b961-7ab50a5b6c7d
< 3.0.0
MEDIUM 5.5 The Rock Convert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's settings … wordfence
c2121162-68db-47c4-80f6-222f013f48c2
< 1.0.36
MEDIUM 5.5 The External Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
c2110dbe-a625-4fa5-8426-8f11b3c33844 MEDIUM 5.5 The GD Mylist WordPress plugin through 1.1.1 does not sanitise and escape some of its settings, allowing high privilege … wordfence
c1ec113c-d11f-4b0b-8d4a-46d37687b3b2
< 1.8.3
MEDIUM 5.5 The Countdown and CountUp, WooCommerce Sales Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
c1d67b80-67b7-4194-ab90-e9f8cea1ac33
< 1.0.6
MEDIUM 5.5 The youForms for WordPress plugin through 1.0.5 does not sanitise escape the Button Text field of its Templates, allowin… wordfence
c133c31e-e80a-4293-b19d-22e8bc8f677b
< 3.8.2
MEDIUM 5.5 The WordPress to Buffer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in vers… wordfence
c10917f9-f0e0-40af-84e3-38f588051186
< 1.1.7
MEDIUM 5.5 The Page Takeover plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
c101b579-de72-4f33-8fd2-7fcd7c25044c MEDIUM 5.5 The DW Promobar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dwpb_bar_text' parameter in v… wordfence
c0ba19a2-0a30-4346-88a2-d1166ab13388
< 3.5.9
MEDIUM 5.5 The Flower Delivery by Florist One plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in … wordfence
c031d2a4-d009-4422-a751-b8476e15a808
< 1.3.2.3
MEDIUM 5.5 The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'facebook_appid' parameter in… wordfence
bff16371-51a9-44c9-ba6f-3680f84b880a
< 6.0.5
MEDIUM 5.5 The WP Social Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters including t… wordfence
bf36c00f-e6a2-4630-b5ef-9015365be436
< 2.3.0
MEDIUM 5.5 The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in al… wordfence
bf02edc9-2bb6-4ceb-b2a1-63f95c8becb3
< 3.1.7
MEDIUM 5.5 The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text… wordfence
be374684-bb02-4d2c-b8a0-ed435c7c8569
< 1.0.4
MEDIUM 5.5 The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its … wordfence
be24d47e-4880-4d7f-9be2-cf8eb1afe888
< 2.8.4
MEDIUM 5.5 The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allo… wordfence
be0db9ff-dc95-4c92-8dc4-472c5df9c0dd
< 1.11.0
MEDIUM 5.5 The Lana Downloads Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the endpoint parameters… wordfence
be091637-0fcb-4d30-8eaa-2fe18d8eb42c
< 1.5
MEDIUM 5.5 The CampTix Event Ticketing plugin before 1.5 for WordPress allows XSS in the admin section via a ticket title or body. wordfence
bddba0a8-03cf-441f-9411-f770766b4f63 MEDIUM 5.5 The Comment Engine Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
bd57edf5-a75e-4677-a51e-9dd262eeba4a
< 4.8.7
MEDIUM 5.5 The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Stored Cross-Site Scripting via the textarea form fiel… wordfence
bd4a1fd2-8831-482d-8ae3-fb78c2657b86 MEDIUM 5.5 The WP DoNotTrack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘whitelist’ and 'blackli… wordfence
bd2f7567-a438-417b-bf0f-dec7a9f098b2
< 3.7.0
MEDIUM 5.5 The WP Mapa Politico Espana WordPress plugin before 3.7.0 does not sanitise or escape some of its settings before output… wordfence
bd248252-4329-4b3c-acf1-3b3d8cc9887c MEDIUM 5.5 The Easy Smooth Scroll Links WordPress plugin before 2.23.1 does not sanitise and escape its settings, which could allow… wordfence
← Prev 1026 1027 1028 1029 1030 1031 1032 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top