πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1032 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a9bd9617-254a-40b3-a1ec-00d30b75e1b8
< 2.7
MEDIUM 5.5 The Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameter in versions up … wordfence
a97b3cf1-e7b7-41c6-8b7a-e06bda77f7f7
< 4.6.5
MEDIUM 5.5 The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme header and footer content in al… wordfence
a90c51d9-c89a-4164-a732-89434a6e0b8e
< 2.1.0
MEDIUM 5.5 The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any parameters used in the post_oxi… wordfence
a8f45c31-6e35-4f28-8f49-74cb08ff65bd
< 1.4.3
MEDIUM 5.5 The Typebot | Build beautiful conversational forms WordPress plugin before 1.4.3 does not sanitise and escape the Publis… wordfence
a8e40f0a-9296-4113-8fff-0aea3c365c1a
< 4.2.6
MEDIUM 5.5 The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to … wordfence
a8546d5d-3ac0-4eb6-9502-07f2590a943b MEDIUM 5.5 The Good & Bad Comments WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high… wordfence
a82c5ca7-5fe5-4817-bf5c-ee7779eb4427
< 4.1.0
MEDIUM 5.5 Cross-site scripting vulnerability in Google XML Sitemaps Version 4.0.9 and earlier allows remote authenticated attacker… wordfence
a81d5615-0b96-4d89-a525-7e80a10a9317
< 1.2.6
MEDIUM 5.5 The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to,… wordfence
a7d5edee-04fb-41e0-be5e-ca3681956d2d
< 2.5.5
MEDIUM 5.5 The Forms for Mailchimp by Optin Cat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the params_st… wordfence
a78c46ac-22dd-48f2-a10b-016205f7e7fa
< 2.2.28
MEDIUM 5.5 The Biteship plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in versions up to, an… wordfence
a741446e-8600-4e02-af76-0d34a491bcfd
< 1.2.52
MEDIUM 5.5 The Sliderby10Web WordPress plugin before 1.2.52 does not properly sanitize and escape some of its settings, which could… wordfence
a6b0b516-af5c-474a-a674-b52cf80207ec
< 2.0
MEDIUM 5.5 The Re:amaze Helpdesk & Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several paramete… wordfence
a62a3a71-0dbb-48d6-ba1a-f218fefac871
< 2.6.12
MEDIUM 5.5 The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before ou… wordfence
a5985318-2ce6-4ecb-a92f-362bc5909bd5
< 11.6
MEDIUM 5.5 The WP Google Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
a4f4605c-d3e4-4f6e-ba47-413049a27455 MEDIUM 5.5 The WP Pipes plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4… wordfence
a4c0b14a-d039-4008-a433-ab3605e2612c MEDIUM 5.5 The Multi Functional Flexi Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `arv_lb[me… wordfence
a4aea6ac-0b36-481c-aa22-db96665404f6
< 7.1.7
MEDIUM 5.5 The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it i… wordfence
a4a885e0-84fb-4f5a-8ef5-6a0a8108d26f
< 2.0.43
MEDIUM 5.5 The Blocksy Companion plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu… wordfence
a44ce6a3-0a9d-4bce-9251-f3a38b000645 MEDIUM 5.5 The Mega Main Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters… wordfence
a3232aaa-189d-42cd-8eec-c167c6aa65f4
< 8.1.15
MEDIUM 5.5 The ActiveCampaign – Forms, Site Tracking, Live Chat plugin for WordPress is vulnerable to Server-Side Request Forgery… wordfence
a27cfa5a-e02a-4c92-8503-2c7cd32fb1f1
< 7.4.6
MEDIUM 5.5 The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the preheader_text value in version… wordfence
a246227c-89c1-46c3-a74c-b5de260d8a19
< 1.31
MEDIUM 5.5 The RSS for Yandex Turbo WordPress plugin through 1.30 does not sanitise or escape some of its settings before saving an… wordfence
a18baa1d-2400-496d-8e8b-1c3983484706
< 3.1.9
MEDIUM 5.5 wordfence
a12f1061-3720-4e99-892d-68c850aa524c MEDIUM 5.5 The Gravity Forms CSS Themes with Fontawesome and Placeholders plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
a107839e-b79b-4868-9232-eca050eb1551
< 5.3.1
MEDIUM 5.5 The WP Travel Engine WordPress plugin before 5.3.1 does not escape the Description field in the Trip Destination/Activit… wordfence
← Prev 1029 1030 1031 1032 1033 1034 1035 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top