🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1041 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
68ec28e8-345c-4017-ab0d-04ac4facd60c
< 1.3.2.6
MEDIUM 5.5 The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3… wordfence
68d7b5d0-c777-4ff9-bdef-a7762cfbdf1a
< 2.9.3
MEDIUM 5.5 The WPLegalPages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wplegalpage' shortcode in versio… wordfence
68d44dd9-cfe4-4bc0-aa2e-9b7fb766870a MEDIUM 5.5 The ScrollReveal.js Effects WordPress plugin through 1.2 does not sanitise and escape its settings, which could allow hi… wordfence
6867d573-4ba1-4b82-b285-0696134d42fc MEDIUM 5.5 The th23 Social WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow high… wordfence
68394503-d989-40d8-b033-24c011294158
< 2.7.3
MEDIUM 5.5 The Tutor LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.2 … wordfence
67b5d20b-4032-4d41-8ab7-6063b7e47827 MEDIUM 5.5 The Great Quotes WordPress plugin through 1.0.0 does not sanitise and escape the Quote and Author fields of its Quotes, … wordfence
67953bf3-5465-4f25-874c-46dff59b2199
< 2.12.0
MEDIUM 5.5 The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing h… wordfence
674df25e-fc37-4f8e-a657-7c493e9bbb15 MEDIUM 5.5 The PopAd plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.4.… wordfence
66519150-7719-4598-8302-b3437719f0a0
< 7.63
MEDIUM 5.5 The All-in-One WP Migration plugin for WordPress is vulnerable to cross-site scripting via the 'storage' parameter in ve… wordfence
6619b370-dd2a-4945-a776-1fecf407119e
< 6.2
MEDIUM 5.5 The wp-Monalisa plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its emoticon parameters in version… wordfence
66082207-33b6-45e4-ae93-24c9a9611300
< 2.3
MEDIUM 5.5 The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in fron… wordfence
65a3604d-eb6b-484f-834a-b3d75fe3bda7 MEDIUM 5.5 The Simple add pages or posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, a… wordfence
65526517-aec5-454b-94c0-973359d840e1
< 1.9.2
MEDIUM 5.5 The Tutor LMS – eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of… wordfence
650f7232-7279-401d-beb1-26f70c69164b
< 1.4.5
MEDIUM 5.5 The connectDaily plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions… wordfence
64f4009e-2715-4c58-acbd-e516f1a76646
< 1.8.8
MEDIUM 5.5 Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lea… wordfence
6447de64-b484-4f64-ad78-7df81b5a0ed7
< 2.9.4
MEDIUM 5.5 The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via shortcode in ve… wordfence
642c03f4-f12c-4ae2-a4ab-4f49d6bd033c
< 4.4
MEDIUM 5.5 The GD bbPress Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in v… wordfence
63c1e570-c0de-44e0-ac39-0b9006c43efa
< 1.1.0
MEDIUM 5.5 The All in One Invite Codes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '$message_text' pa… wordfence
63192a95-778b-452b-9081-cf20dc7f7ec1 MEDIUM 5.5 The Developer Formatter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all vers… wordfence
626dac34-6b25-42c9-8f7d-9899e4bcc039 MEDIUM 5.5 The WordSurvey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sounding_title’ parameter … wordfence
6230275e-8742-40f4-869f-a0e0984d85ba
< 1.40
MEDIUM 5.5 The Playlist for Youtube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions … wordfence
61ec0e78-b367-438f-929d-94e055c83477 MEDIUM 5.5 The Recently viewed and most viewed products plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an un… wordfence
61d6b2b8-dcaa-4419-b61d-4def743def95 MEDIUM 5.5 The Bookshelf WordPress plugin through 2.0.4 does not sanitise or escape its "Paypal email address" setting before outpu… wordfence
617c850f-8d7b-42d4-ac40-2381c4c6bde6 MEDIUM 5.5 The WP Humans.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
60ea00e2-e33d-452d-969b-4022d6a00417
< 1.4.4
MEDIUM 5.5 The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing h… wordfence
← Prev 1038 1039 1040 1041 1042 1043 1044 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top