🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1042 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5f75e37d-a94e-4103-b706-5fead24f1f73
< 2.0.2
MEDIUM 5.5 The WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce plugin for Word… wordfence
5f6ee92e-4ccb-41b3-855f-adbfae4888ee MEDIUM 5.5 The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio WordPress plugin through 6.1.2 does not sanitis… wordfence
5ef104ae-b67c-4669-adeb-e5397561c0ae
< 3.0.6.6
MEDIUM 5.5 The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in version… wordfence
5ee5e650-5a52-4921-92c3-3ea1a43fc238 MEDIUM 5.5 The VaultRE Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
5ebe34fd-6860-4074-ae86-37f979f54dc9
< 4.1
MEDIUM 5.5 The WordPress Comments Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Error Message se… wordfence
5e7cde2e-28e6-417a-900a-38d0a77800d3
< 3.1.3
MEDIUM 5.5 The eu-cookie-law plugin through 3.0.6 for WordPress (aka EU Cookie Law (GDPR)) is susceptible to Stored XSS due to impr… wordfence
5e584e2e-0625-4777-b44c-2d682c9a4c34
< 1.1.63
MEDIUM 5.5 The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high… wordfence
5db41cdb-0795-43e7-bd36-9a85a882a760
< 2.0.1
MEDIUM 5.5 The Sync QCloud COS WordPress plugin before 2.0.1 does not escape some of its settings, allowing high privilege users su… wordfence
5d858f96-7363-4098-af2d-f6f96fc80071 MEDIUM 5.5 The Advanced Youtube Channel Pagination plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missin… wordfence
5d652b50-9c9c-4418-bd6b-ae862a1c8786
< 4.1.3.2
MEDIUM 5.5 The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom… wordfence
5d45d870-dd00-40aa-9e98-4be4d06b3a0a
< 1.7.8
MEDIUM 5.5 The Multi Step Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its form fields in … wordfence
5d276502-6154-468e-b028-eadf29debe56 MEDIUM 5.5 The Retain Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
5ccd7f4e-46c6-4783-9a3f-30c72bbc981e
< 5.9
MEDIUM 5.5 The WP Database Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versi… wordfence
5c79cbc1-4d8f-4330-b063-e5987238fca1
< 3.1.9.3
MEDIUM 5.5 The WordPress Countdown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters … wordfence
5c59cfc2-2a2c-4b0b-88f7-f6a96caa25c4 MEDIUM 5.5 The Admin Pack by SITE CASEIRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sc_plugin_admi… wordfence
5c4fb14c-de6d-4247-8f83-050f1350f6a2
< 2.88.1
MEDIUM 5.5 The WP-UserOnline plugin for WordPress has multiple Stored Cross-Site Scripting vulnerabilities in versions up to, and i… wordfence
5be89866-f60d-4cc6-ac00-80ad15a07fe3
< 1.69.1
MEDIUM 5.5 The WP-Ban plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in vers… wordfence
5bd803c7-c120-4967-84e3-5f97fc35a79e
< 1.7.4
MEDIUM 5.5 The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing … wordfence
5aff79ef-6c96-4386-abf1-b4e6931ef0d2
< 2.0.10
MEDIUM 5.5 The Tutor LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the topic name and lesson name param… wordfence
5aa934c4-f432-43ab-a542-21579a4a41f5 MEDIUM 5.5 The AppBanners plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.1… wordfence
59b90bf9-c053-4c70-ab30-e1565a65cbce
< 2.1.28
MEDIUM 5.5 The wpDataTables plugin <= 2.1.27 is vulnerable to authenticated (admin+) Stored Cross-Site Scripting wordfence
598768fe-e36d-48d8-925e-64513f36b18b
< 3.2.12
MEDIUM 5.5 The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several fields i… wordfence
58b8e6f5-5cf8-4dbb-89e9-69266bdc1a30 MEDIUM 5.5 The WP Customize Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘changelogourl’ and… wordfence
5760933b-30e6-465b-9b94-c913b21f07fd MEDIUM 5.5 The Category and Taxonomy Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_category_ima… wordfence
57156ebc-2858-4295-ba08-57bcab6db229
< 2.2.5
MEDIUM 5.5 The WooCommerce Shipping & Tax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown paramete… wordfence
← Prev 1039 1040 1041 1042 1043 1044 1045 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top