🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1045 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4669b08a-acaf-4a24-b71e-e3a6c8fcf557
< 3.6.0
MEDIUM 5.5 The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
463441f9-1a32-4df3-a8d1-324ed9faa5ea
< 3.0.5
MEDIUM 5.5 The Mobile Contact Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
462372ab-8f83-4b75-b3dd-674199e1eeee
< 5.3.1
MEDIUM 5.5 The Mailjet Email Marketing plugin for WordPress is vulnerable to authenticated stored cross-site scripting in versions … wordfence
45e61d76-085d-48ba-b5ae-cc75f91d1250
< 3.2
MEDIUM 5.5 The Rencontre – Dating Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'textmail' and 'text… wordfence
45700ca9-8bda-4148-b19f-86ed39c60117
< 8.1.12
MEDIUM 5.5 Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plu… wordfence
455b0b34-1421-46eb-8fcf-3b68c5068249
< 4.1.2
MEDIUM 5.5 The XML Sitemaps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up… wordfence
4554235f-1790-4be7-a575-02fb18c6a4a9 MEDIUM 5.5 The Videos sync PDF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versi… wordfence
44a8b7fb-7c91-4a85-bf16-4371fde6945f
< 2.2.7
MEDIUM 5.5 The Responsive Tabs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Slides Per View paramet… wordfence
445e762c-7e90-4994-8542-31a84bc91388 MEDIUM 5.5 The Interactive Human Anatomy with Clickable Body Parts plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
4419a302-4305-44f8-a256-dd276b5cd751
< 1.14.8
MEDIUM 5.5 The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to,… wordfence
43df6d4d-960e-4eb7-809b-684ba0d67f58
< 4.4.2
MEDIUM 5.5 The Duplicate Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Duplicate Post Suffix setti… wordfence
43c9dcec-f769-4c55-93d0-c2aa45a4fa16
< 4.5.1
MEDIUM 5.5 The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several form fields in versions u… wordfence
438bbd0f-5204-4a71-9730-efa51d864832
< 1.7.5
MEDIUM 5.5 The Faculty Staff and Student Directory Plugin – Campus Directory plugin for WordPress is vulnerable to authenticated … wordfence
436cd742-c271-4eb7-96a3-cd6af046d26f
< 0.9.3
MEDIUM 5.5 The Highlight WordPress plugin before 0.9.3 does not sanitise its CustomCSS setting, allowing high privilege users to pe… wordfence
4364e713-8463-4088-b198-ed8237e86d42
< 2.5.8
MEDIUM 5.5 The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wppb_general_settings[m… wordfence
4261c81e-13a2-4022-8048-aeb0ea4e9ee4 MEDIUM 5.5 The Frndzk Expandable Bottom Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text' parameter … wordfence
42308a6e-cb04-42dc-90b0-9b40c264ad53 MEDIUM 5.5 The RandomQuotr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
42156e9f-711a-4592-b92c-d4af845d686a MEDIUM 5.5 The Better Delete Revision plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$bdr_rev_no’ p… wordfence
41d73ce6-a256-43ef-8627-c6f6d6635e3e
< 1.2.0
MEDIUM 5.5 The JobBoardWP – Job Board Listings and Submissions WordPress plugin may be vulnerable to Stored Cross-Site Scripting … wordfence
41428fa7-455b-44be-8ec1-977e8cf8a303
< 8.7.0
MEDIUM 5.5 The Slider Hero with Animation, Video Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a… wordfence
4101bd5e-94fb-4ec5-9d25-581c3211ffa7 MEDIUM 5.5 The Add Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various plugin settings parameter… wordfence
40f909ca-aadd-4a3d-9e25-24265abdee73 MEDIUM 5.5 The WordPress Auction Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
404fab1b-45e9-470a-a0ae-73c01386d95e
< 5.0.10
MEDIUM 5.5 The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all… wordfence
3feb84c9-fc98-4f59-a124-b6434e5b8a44 MEDIUM 5.5 The Sidebar Widgets by CodeLights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Extra CSS… wordfence
3fad525f-8dcb-453c-9e53-2335c6d1c46d
< 1.42
MEDIUM 5.5 The We’re Open! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions u… wordfence
← Prev 1042 1043 1044 1045 1046 1047 1048 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top