🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1038 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
81e1bc49-8ed0-4605-bc81-682b89f53796
< 1.4.8
MEDIUM 5.5 The WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce plugin for WordPress is vulnera… wordfence
81bcbf7d-d33f-4cf2-8411-613cf54095b4
< 5.2.3
MEDIUM 5.5 The Print, PDF, Email by PrintFriendly WordPress plugin before 5.2.3 does not sanitise and escape the Custom Button Text… wordfence
8035023c-347f-4227-98cb-5b277fba4812 MEDIUM 5.5 The Google Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions u… wordfence
801132f5-e4ea-4d56-8429-9f33896f6dff
< 3.3.17
MEDIUM 5.5 wordfence
7fb7dd8f-6258-46e1-9cc5-87ec73d5736c
< 5.1.8
MEDIUM 5.5 The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… wordfence
7f91992e-33fb-4384-af34-e27f68e1ca6e
< 4.0.0
MEDIUM 5.5 The Login by Auth0 Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in version… wordfence
7f8839cf-9e48-4981-8a0d-bb0c06cdf441 MEDIUM 5.5 The Client Dash plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
7f6c33f4-58e7-4a0b-8293-5cb951f63ffc
< 4.2.22
MEDIUM 5.5 The Webba Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… wordfence
7f46ab3d-83fc-46a2-863e-7ce9b5391524
< 1.2.2
MEDIUM 5.5 The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting… wordfence
7e9dcedd-aa81-47c4-9fc5-cecc7bc394b5
< 5.3.3
MEDIUM 5.5 The MonsterInsights – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
7e7741d1-8b30-460d-bf1b-edc475841c71
< 1.2.54.1
MEDIUM 5.5 The MailOptin plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.54.0 due … wordfence
7e49d389-0ae8-48e1-8ff7-67ddaa5b2867
< 5.0
MEDIUM 5.5 The Social Media Follow Buttons Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alignme… wordfence
7e10babc-fc65-46f9-8b88-95b00f66d01b MEDIUM 5.5 The Showing URL in QR Code plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
7dfa84ed-0edf-4a75-8ec3-986c3880353c
< 3.2.0
MEDIUM 5.5 The Easy Social Icons plugin for WordPress is vulnerable to admin-level stored Cross-Site Scripting due to missing sanit… wordfence
7d1e0423-a91b-4096-ad65-19e2d11cfea1 MEDIUM 5.5 The Birthdays Widget WordPress plugin through 1.7.18 does not sanitise and escape some of its fields, which could allow … wordfence
7cfeed0f-ab3e-4b35-9b69-08cc7e7ffb45 MEDIUM 5.5 The Flexi Quote Rotator WordPress plugin through 0.9.4 does not sanitise and escape its settings, allowing high privileg… wordfence
7cd3c84b-dacc-44e8-a236-bfc80e6dceba MEDIUM 5.5 The content-grabber plugin 1.0 for WordPress has XSS via obj_field_name or obj_field_id. wordfence
7c9a2045-7d24-4871-b962-32bc0fdf5476
< 1.7.2
MEDIUM 5.5 The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do n… wordfence
7c6ea33f-ee43-4df8-9633-60303b68b859
< 1.1.34
MEDIUM 5.5 The AdPlugg WordPress Ad Plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.1.34 due to ins… wordfence
7c4ceb2e-c718-43e2-bb7b-ab0404271134
< 1.4.5
MEDIUM 5.5 The Passwords Manager plugin is vulnerable to Cross-Site scripting via the pwdms_csv_category parameter in versions up t… wordfence
7bde76d9-34f3-46c9-a05a-e5204b661b26 MEDIUM 5.5 The Advanced WP Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various setting parameters… wordfence
7bc9f86f-fd60-48bc-8df0-3b122facb0a0
< 5.0
MEDIUM 5.5 The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, whi… wordfence
7b4d99d9-e58b-47c5-bb10-35f09b25cbf4
< 3.90.1
MEDIUM 5.5 The FG Drupal to WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and … wordfence
7b49af95-2310-4f71-921b-ee66588dd6d5
< 6.4.0
MEDIUM 5.5 The WP Affiliate Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in ve… wordfence
79cc1f11-9b53-4e71-b0cc-8f8ebd4a5f32
< 1.1.25
MEDIUM 5.5 The SVG Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all ver… wordfence
← Prev 1035 1036 1037 1038 1039 1040 1041 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top