🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1047 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
38e831b4-8284-4fad-ac24-a2f08053c53e
< 20221201
MEDIUM 5.5 The Simple Basic Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its setti… wordfence
38d7c79f-a4a2-447d-88a2-ad75b53ac8bc
< 3.6.10
MEDIUM 5.5 The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'label' parameter… wordfence
38979e27-2023-4f84-a708-1732b4117066
< 3.7.40
MEDIUM 5.5 WordPress Core is vulnerable to Stored Cross-Site Scripting via the Customizer in versions up to 6.0.3. This is due to i… wordfence
387ccc20-1b84-4e7c-b4bc-75ad6dad8376 MEDIUM 5.5 The WP Next Post Navi plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
385a82ff-50ad-4787-845b-fb5f639f6466
< 21.1
MEDIUM 5.5 The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 21.0 d… wordfence
37f3aca7-b728-4a27-9e08-bdc9ca2f8f0c
< 2.9.5
MEDIUM 5.5 The Simple Job Board WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $… wordfence
37bfc71f-e1f9-4374-ab65-9b1c321ff386
< 1.1.2
MEDIUM 5.5 The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high p… wordfence
3732bf4c-e5e4-4947-9044-9a49e7547cf3 MEDIUM 5.5 The WP Total Hacks plugin for WordPress is vulnerable to stored Plugin Options Update and Cross-Site Scripting in versio… wordfence
36f107cf-4b85-4016-b7af-b73a706cf1a6
< 2.6.9
MEDIUM 5.5 Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticate… wordfence
36b71a50-270a-4960-bf31-e888df84e619
< 1.7.2
MEDIUM 5.5 The ShiftNav – Responsive Mobile Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… wordfence
360cba3a-dfae-4b1c-9b33-f531fb9b12e0
< 5.0.5
MEDIUM 5.5 The WP Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attachment’ parameter … wordfence
35f2d80a-891a-4616-a3f6-01bbf12f5f10
< 3.3.2
MEDIUM 5.5 The Author Bio Box WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation an… wordfence
35b46587-1c6e-4d3f-a8d0-e7797cee882d
< 1.1.2
MEDIUM 5.5 The GTM Server Side plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'GTM Server Side url' fiel… wordfence
35697cf5-4494-40f6-8772-dfa417ae6bcb
< 3.4.8
MEDIUM 5.5 The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
350c23c6-6201-4dd5-9594-edb7d8ad926c MEDIUM 5.5 The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter i… wordfence
3504b703-b95b-4d22-8883-a575b398c9ea
< 2.3.8
MEDIUM 5.5 The Request a Quote WordPress plugin through 2.3.7 does not sanitise and escape some of its settings, allowing high priv… wordfence
35027df9-ae55-453f-bb42-4b2664d66293
< 2.6.4
MEDIUM 5.5 The Statify – Extended Evaluation plugin for WordPress is vulnerable to CSV Injection in versions up to, and including… wordfence
3424c187-cf71-41f0-abb8-f0e843750465
< 1.12.3
MEDIUM 5.5 The Forms WordPress plugin before 1.12.3 did not sanitise its input fields, leading to Stored Cross-Site scripting issue… wordfence
33bf39f8-6f56-4089-bb46-5d401af72953
< 3.3.103
MEDIUM 5.5 The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
33adf97e-c0f9-488b-b9cf-e703578c4d1e
< 2.1.11.1
MEDIUM 5.5 The bbPress Voting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up t… wordfence
336eb1fb-dc94-417d-b9b6-488c105aab1e
< 1.3
MEDIUM 5.5 The Find and Replace All plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘findstr’ and 're… wordfence
33166510-41b2-4e9a-8bd7-501235729346
< 1.0.4
MEDIUM 5.5 The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set… wordfence
32682598-ad1c-4aa1-bdf2-a7966a4d1dbe
< 1.1.4.1
MEDIUM 5.5 The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulne… wordfence
32272237-43c1-4b77-b586-9fad4af279e4
< 3.2.4
MEDIUM 5.5 The Yoast Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
31579f6d-9a89-45e3-adfb-d59823a83c07
< 1.5.46
MEDIUM 5.5 Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploita… wordfence
← Prev 1044 1045 1046 1047 1048 1049 1050 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top