🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1039 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
79b859ef-5417-47e5-8b9a-763c62a6a127
< 1.4
MEDIUM 5.5 The VDZ Verification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meta Tag settings in vers… wordfence
797c2c60-51bd-4992-86fc-23fda363ad76
< 2.1.3
MEDIUM 5.5 The Related Posts for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_tex… wordfence
796e35bc-db5f-45e3-8f79-73b30add877f
< 2.3.3
MEDIUM 5.5 The Custom Post Types and Custom Fields creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via so… wordfence
78fce739-5cc7-4a7f-bf3b-665f35ef3579
< 7.1.2
MEDIUM 5.5 The LayerSlider WordPress plugin before 7.1.2 does not sanitise and escape Project's slug before outputting it back in v… wordfence
78f3e63b-1d60-47bb-9366-dbdd81d6ed19
< 1.9.2
MEDIUM 5.5 The SlideShare for WordPress by Yoast plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $id vari… wordfence
7716e77f-e899-4046-9421-86fc0c36c245 MEDIUM 5.5 The HTTP Headers plugin for WordPress is vulnerable to CRLF Injection in all versions up to, and including, 1.19.2. This… wordfence
76d96ab1-e667-4242-aee3-95f8dfb07ccd MEDIUM 5.5 The WordPress File Monitor plugin is vulnerable to Cross-Site Scripting in versions up to, and including, 2.3.3 due to i… wordfence
76d850dd-75f3-4671-9561-0e361d09a121
< 2.7.29
MEDIUM 5.5 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sever… wordfence
76c0d4f8-230d-452a-b39d-cbcb0af0fd72
< 1.8.8
MEDIUM 5.5 The Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.8 is affected by a local file inclusi… wordfence
7691152e-f962-4d82-b877-df1345b703cc MEDIUM 5.5 The add2fav plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 due … wordfence
766c2aa5-e829-45b9-b6e3-0a522a0977d4
< 1.1.4
MEDIUM 5.5 The Posts and Users Stats plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.1.3. T… wordfence
763a9aff-9bc0-4c79-9383-778a9034b436
< 4.0
MEDIUM 5.5 The Groundhogg plugin for Wordpress is vulnerable to Stored Cross-Site Scripting via the ‘label' parameter in versions… wordfence
748e2f67-cd28-4d02-9460-ef88a609d811
< 3.1.4
MEDIUM 5.5 The mTouch Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.… wordfence
748d01ca-9dd5-4d03-88e7-e80932744fdc
< 4.4.7
MEDIUM 5.5 Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plug… wordfence
72e1fbce-86ae-4518-a613-7c322193acf4
< 2.8.6
MEDIUM 5.5 The Friends plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.… wordfence
71f059ba-1874-4e8a-80e9-3f7826f9341d
< 1.5.7.7
MEDIUM 5.5 The Simply Schedule Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameter… wordfence
712e9754-a6f2-43b5-97be-9d23970b46ea MEDIUM 5.5 The Indeed Job Importer WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validati… wordfence
70fee28f-7a2b-4d57-9fca-04a805dca3f6 MEDIUM 5.5 The Float to Top Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
70d046c9-a0c2-4059-aa1d-47caa1ffe76c
< 1.4.1
MEDIUM 5.5 The Scroll To Top plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘text’ parameter in vers… wordfence
70aaef82-c93b-4f2b-8d57-6c28d45942ad MEDIUM 5.5 The EditableTable WordPress plugin through 0.1.4 does not sanitise and escape any of the Table and Column fields, which … wordfence
6ff53647-572f-419f-ad39-965658a10263
< 3.8.0
MEDIUM 5.5 The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.7… wordfence
6ff184e6-c36b-4bbb-8dc2-f87d1d800d53 MEDIUM 5.5 The Coming Soon – Under Construction plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
6fbd5ac8-11c0-4628-9a7b-620b17cc8ba6
< 1.1.36
MEDIUM 5.5 The OOPSpam Anti-Spam plugin for WordPress is vulnerable to Stored Cross-Site Scripting via options such as 'oopspam_wpr… wordfence
6f95c786-900b-4069-8509-fab623f5f988
< 1.16.5
MEDIUM 5.5 The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Cookie Time field in versions … wordfence
6f947843-7a6f-48b0-b3cd-2f3dd1708898
< 1.1.19
MEDIUM 5.5 An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi… wordfence
← Prev 1036 1037 1038 1039 1040 1041 1042 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top