🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1049 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
27885b7f-ef8c-45ea-995c-92cd1939e1c5
< 3.0.1
MEDIUM 5.5 The WP Custom Cursors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor_text’ parame… wordfence
277942cb-f4ca-4197-8f61-2e0cb03115a6
< 1.7.4
MEDIUM 5.5 The Digital Publications by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several para… wordfence
27478d23-961d-4a88-adf5-c3cdd79cc10c
< 1.19.2.1
MEDIUM 5.5 The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitize and escape imported CSV dat… wordfence
27277b3d-b4f9-4d0c-a213-988a9b8fcd34
< 2.3.1
MEDIUM 5.5 The Invitation Based Registrations WordPress plugin through 2.2.84 does not sanitise and escape some of its settings, wh… wordfence
27254411-3ae7-4659-b3c1-1c18911e3bfb
< 1.5
MEDIUM 5.5 The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its sett… wordfence
269b0edd-2358-4a71-8fbe-de9a1c939807 MEDIUM 5.5 The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
2685c3e9-cb68-4d59-b7ef-ebe40419fb59 MEDIUM 5.5 The Awesome Surveys plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
26529849-c52c-40e5-8085-6764c22a03e7
< 2.3.1
MEDIUM 5.5 The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field settings in versions u… wordfence
26237984-d7b5-4a55-91f8-a2816f3d2e94
< 1.0.3
MEDIUM 5.5 The Accessibility plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'attachments_alt' and 'attac… wordfence
259ed1a0-1bfa-4d38-845c-e5655c330702
< 3.1.9.2
MEDIUM 5.5 The WordPress Countdown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters … wordfence
2505ffdd-d697-4c69-8f75-0bc4d09e1b1f
< 3.0.5
MEDIUM 5.5 The Inline Related Posts plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.… wordfence
24eb524c-1705-43a5-8041-4549ebb49155 MEDIUM 5.5 The IP Blacklist Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
24bdffdc-1a4d-4a1c-8393-cf89f0a63bf9 MEDIUM 5.5 The Cookie Notice Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu… wordfence
24ba8d30-843f-4178-9b10-3c3dc720205c
< 2.3.3
MEDIUM 5.5 Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Adam Skaat's Countdown & Clock plugin <= 2.3.2… wordfence
24a041d0-d443-453d-bd7d-65cceee48b14
< 1.8.9
MEDIUM 5.5 The WPFrom Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to… wordfence
247a095b-0a92-4fee-85cf-c3041a061d62 MEDIUM 5.5 The HTML5 Responsive FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
244a23a2-8899-4ab4-8f8d-62756e4ea56b
< 2.0.11
MEDIUM 5.5 Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "A… wordfence
240691c4-35c5-40e1-b1ab-a500ffcdac73
< 2.45.1
MEDIUM 5.5 The Simple Giveaways plugin for WordPress is vulnerable to Stored Cross-Site Scripting via certain form, prize, and shar… wordfence
23f58949-6cc7-45a3-a6a0-58213bb03679 MEDIUM 5.5 Authenticated (contributor of higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress … wordfence
23a2fd80-65cb-4e92-978d-c365f08b4c0b MEDIUM 5.5 The Subpages Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subpages_save_postdat… wordfence
22fa9343-0b6e-47d5-9ebc-2c8902428b8b
< 1.1.0
MEDIUM 5.5 The Limit Login Attempts Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ve… wordfence
22de2da7-f7db-46de-9305-52bce6e56937 MEDIUM 5.5 The WP LESS to CSS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions … wordfence
2294565a-987e-4837-ab22-6e7bff498044
< 2.1.0
MEDIUM 5.5 The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pages’ parameter used in t… wordfence
222aa8cb-95f4-4fe1-82c8-3acf82960cc0
< 3.1.4
MEDIUM 5.5 The Simply Static plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
222678d0-cb1f-43c6-a6f0-37ea0be8cd3d
< 3.6.11
MEDIUM 5.5 The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters fo… wordfence
← Prev 1046 1047 1048 1049 1050 1051 1052 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top