🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1031 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b3d71289-e5a3-4145-817f-c2cac8405202
< 3.4.0
MEDIUM 5.5 The EventPrime plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
b31a54f1-de87-49ac-bce1-e0ea295af325
< 2.3.47
MEDIUM 5.5 The Slide Anything – Responsive Content / HTML Slider and Carousel plugin for WordPress is vulnerable to Stored Cross-… wordfence
b2f4efa2-ddf6-46a7-9bde-aa1bcbbd2999
< 1.0.12
MEDIUM 5.5 The Launcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.11 … wordfence
b2b1db53-227c-4887-b24d-37c0d2bedf69
< 2.2.2
MEDIUM 5.5 The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters, with at least one… wordfence
b290e792-2473-4ba5-b66c-b6ca65445c0e
< 2.6.9
MEDIUM 5.5 The Responsive Starter Templates – Elementor & WordPress Templates is vulnerable to Stored Cross-Site Scripting in ver… wordfence
b1db421d-d935-4441-ae5e-cc01123e80e8
< 2.7.1.1
MEDIUM 5.5 The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
b192d5d5-3bb9-4600-849e-2bb3c06009af
< 9.0.0
MEDIUM 5.5 The News Announcement Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in… wordfence
b12c0524-d991-4f96-8646-f4203880558c
< 2.1.5
MEDIUM 5.5 The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters … wordfence
b1280aec-f253-404e-b03c-d1b8416a6e7d
< 7.2.4
MEDIUM 5.5 The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘lae_theme… wordfence
b11f2ad4-5a89-4387-a307-350cead20491 MEDIUM 5.5 The Evaluate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 due… wordfence
b10941c7-40f1-4157-a9d9-40844d25b22b
< 4.4.0
MEDIUM 5.5 The No API Amazon Affiliate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
b01ce539-08f4-48f7-9ddc-56e87a2c91cc
< 1.2.12
MEDIUM 5.5 Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.… wordfence
afd67c36-31ec-4e44-bad5-a018834ccfbc MEDIUM 5.5 The qTranslate X plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4… wordfence
afb53b31-c179-4d11-845f-8acd18638038
< 4.1.5
MEDIUM 5.5 The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the cat… wordfence
af22365c-7d4b-48f3-b33d-d627169fda6f
< 1.0.3
MEDIUM 5.5 The GetYourGuide Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘partner_hash’ … wordfence
aefb7e34-ec48-4e29-b3aa-85901e12d21c
< 0.14
MEDIUM 5.5 The Mantenimiento web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
aec57fbd-83c5-4080-9372-66500c299afc
< 0.8.40
MEDIUM 5.5 The Social Like Box and Page by WpDevArt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via select el… wordfence
ae88e065-4601-4f0e-80a4-0f011bb0d347
< 1.1.19
MEDIUM 5.5 An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi… wordfence
ad5a13d9-5ba4-4e66-8374-f45bcd6c716f
< 2.8
MEDIUM 5.5 The Duplicate Page and Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Settings->Dupli… wordfence
acbe0ccd-f814-4cdd-ab70-6b8d29166e25
< 1.1.10
MEDIUM 5.5 The VikRentCar Car Rental Management System WordPress plugin before 1.1.10 does not sanitise the 'Text Next to Icon' fie… wordfence
abe8efec-8f00-40bc-bc28-98435d11ebd3
< 2.4.3
MEDIUM 5.5 The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels b… wordfence
aba33487-f6c5-41e9-9500-73bef37381e6
< 3.7.10
MEDIUM 5.5 Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-wid… wordfence
aafbdd50-c78b-4aad-a3e2-f1339d698e77
< 2.0.9
MEDIUM 5.5 The Fitness calculators plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions… wordfence
aa8df7ee-5308-4993-ac49-e2e58f3eaf60
< 1.6.0
MEDIUM 5.5 Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow re… wordfence
a9e67057-7086-4108-a629-87610a12ec19
< 1.6.14
MEDIUM 5.5 The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via contact form settings in versions up t… wordfence
← Prev 1028 1029 1030 1031 1032 1033 1034 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top