ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1046 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3f6d9c23-53e9-4393-beff-2f996c279ad8 MEDIUM 5.5 The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image me… wordfence
3f5eef96-b9db-444b-82b8-86132376e29c
< 3.2.2
MEDIUM 5.5 The Salat Times plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Widget Title parameter in vers… wordfence
3f3aec3a-c1d3-4f7f-9f45-7a3ec42ce260
< 1.2.53
MEDIUM 5.5 The Sliderby10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via slider row links in versions up … wordfence
3e7105d3-3208-4964-8d21-172059cbbd63
< 2.1.7
MEDIUM 5.5 The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.6 due… wordfence
3d8b8f54-b2af-42dd-af82-c1e8726c87e2
< 4.2
MEDIUM 5.5 The Text Hover WordPress plugin before 4.2 does not sanitize and escape the text to hover, which could allow high privil… wordfence
3d54f585-0116-4517-84f1-271e89a05539
< 4.5.1
MEDIUM 5.5 The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_user_cover_default_imag… wordfence
3cf1983b-4cb7-4738-9f19-2c530a9939e0
< 3.7.2
MEDIUM 5.5 The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio… wordfence
3cea044c-3117-4722-a696-5b7368d31d63
< 0.1.6
MEDIUM 5.5 The WordPress Filter Gallery Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ufg_gallery_filte… wordfence
3c547a2b-98fb-4936-88a5-31e5c879a364
< 1.14.12
MEDIUM 5.5 The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which cou… wordfence
3c070b9c-5bed-4f9f-8d96-70958bf294cf MEDIUM 5.5 The iFeature Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versio… wordfence
3bb6e8f8-690a-49cb-ac00-f572bef8b8f7
< 1.1.19
MEDIUM 5.5 An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi… wordfence
3b6ac92f-2ad1-4528-b157-5e49d6f224a5
< 1.3
MEDIUM 5.5 The WP Total Branding – Complete branding solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
3b0d6b1f-5601-4c96-893c-e296511a2996
< 10.4.3
MEDIUM 5.5 The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an … wordfence
3abbc407-f660-4b1f-9d48-436320e5fdd7 MEDIUM 5.5 The Members Import plugin for WordPress is vulnerable to Self Cross-Site Scripting via the user_login parameter in an im… wordfence
3a84a021-5014-4848-a77f-d3f4802c9395
< 5.13.1
MEDIUM 5.5 The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an … wordfence
3a75ff86-dc4d-4519-8cc5-183afc00cb65
< 1.4.9.4
MEDIUM 5.5 The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! Wor… wordfence
3a581d5e-11c3-468a-b4a1-6507f898f5ed
< 1.6.9.1
MEDIUM 5.5 The Backup Guard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6… wordfence
39f1ddd0-c26b-4754-a78a-c64fab75f238
< 3.6
MEDIUM 5.5 The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of i… wordfence
397e9d40-ecd3-4800-9191-c7e4805bcb31 MEDIUM 5.5 The Elfsight Yottie Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
39722a07-abfe-4956-b5d0-8ece06913a85
< 8.0.0
MEDIUM 5.5 The Really Simple SSL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu… wordfence
393a856e-dc13-4fb6-8ff3-5880631953c4
< 4.2
MEDIUM 5.5 The Extra Product Options for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
3936d7dc-840e-41fc-8af4-db40c0cff660
< 2.13.10
MEDIUM 5.5 The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… wordfence
391d65a7-1675-4eae-b129-a1208cd95669
< 2.0.6
MEDIUM 5.5 The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via API key in versions up to, … wordfence
39041c15-dc85-49bc-b5d1-5b4bff05397b
< 1.9.8.4
MEDIUM 5.5 The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form … wordfence
38efd6d6-b931-41a7-b55d-b98cdeef4145
< 1.14.6
MEDIUM 5.5 The WPGraphQL plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.14.5… wordfence
← Prev 1043 1044 1045 1046 1047 1048 1049 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top