ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1048 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
31496229-bf54-466c-a87b-cc32e65500a4
< 5.9
MEDIUM 5.5 The WP Database Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versi… wordfence
31058d2e-9c23-4057-89a4-5847b6012330
< 1.1.3
MEDIUM 5.5 The TinyMCE Custom Styles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio… wordfence
301d273e-5cd2-49b8-b2ce-b30731ab4550
< 2.11.6
MEDIUM 5.5 The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the… wordfence
2f226493-4787-4d99-999d-3e3916a8c41d
< 5.8.23
MEDIUM 5.5 The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege u… wordfence
2ef5b0de-0b8b-4286-86ea-6dca0dbc1a52 MEDIUM 5.5 The Waiting: One-click countdowns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown na… wordfence
2e806895-40c9-44f5-97f8-becfa52c2559
< 2.1.0
MEDIUM 5.5 The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘notice’ parameter used in … wordfence
2df8ba02-30b0-49af-82cf-a0d2fd994ea2
< 8.4.4
MEDIUM 5.5 The Slider Hero plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slider title parameter in vers… wordfence
2dccdaa8-5095-42c4-9ca8-90fb444c0ae4
< 3.7.22
MEDIUM 5.5 Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name. wordfence
2da02a0e-4bc5-4dc6-b46e-7e74e0eb36dd
< 3.6.4
MEDIUM 5.5 The Dokan plugin for WordPress is vulnerable to Stored Cross-Site Scripting via product reviews in versions up to, and i… wordfence
2d964e1e-6361-435b-8527-e241f5a28b0e MEDIUM 5.5 The Comment Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
2d5fb5c8-3e4d-4268-8b21-b65b7d7b68f2
< 3.0.1
MEDIUM 5.5 The Smart Post Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pagination Color setting i… wordfence
2c4749b8-cfaf-4a6e-a093-0c2bfd22b809
< 6.0.8
MEDIUM 5.5 The WP Maintenance plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 6.0.7 du… wordfence
2c2c8025-6a1b-475d-bc28-9f2ec3ad7bdc MEDIUM 5.5 The WP Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in vers… wordfence
2b32cc12-c8d5-40b8-9510-42699beec581
< 1.15.28
MEDIUM 5.5 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Store… wordfence
2ae939f4-5a90-48ca-ae13-2ccbd6d8d08a MEDIUM 5.5 The Simple Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including 0… wordfence
2ad7fd59-e4a2-46e7-9232-d76255a6b0b4
< 4.16.6
MEDIUM 5.5 The Leaky Paywall WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and… wordfence
2ab1a623-5726-45ca-9667-ed926c5d3364
< 1.1.16
MEDIUM 5.5 The Alojapro Widget WordPress plugin through 1.1.15 doesn't properly sanitise its Custom CSS settings, allowing high pri… wordfence
2a677eed-0344-457e-aa5f-3b94a624462c MEDIUM 5.5 The SEO Smart Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
29eeac86-6b33-49e6-a7e1-c80dee383d6f
< 6.3
MEDIUM 5.5 The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulne… wordfence
2921ea67-e88a-489a-8c45-cfe458f29d2b
< 1.3.30
MEDIUM 5.5 The HTML Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
28e9c77c-5c36-4449-ab90-86f2385ba1ae
< 5.2.0
MEDIUM 5.5 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross… wordfence
28ccae6b-c330-4811-9cd8-eeb2c91c2f55 MEDIUM 5.5 The My Bootstrap Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
287c6cdc-f534-4b87-8a97-ee1e3666cd25
< 13.0.6
MEDIUM 5.5 The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high priv… wordfence
282fabde-c3a5-49d0-987a-39f106f766cf
< 3.0.7.2
MEDIUM 5.5 The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its T… wordfence
27f09e0e-ddd0-4440-9a58-a7fc60b49776 MEDIUM 5.5 The Easy Preloader WordPress plugin through 1.0.0 does not sanitise its setting fields, leading to authenticated (admin+… wordfence
← Prev 1045 1046 1047 1048 1049 1050 1051 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top