🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1050 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
21dd96e0-8c1c-4593-8a75-079125192001
< 2.8.0
MEDIUM 5.5 The CM Download Manager plugin for WordPress is vulnerable to Authenticated Stored Cross-Site Scripting via the ‘filen… wordfence
21dd21cb-35b7-47df-a9f0-6fd92c45a8ce
< 1.4.6
MEDIUM 5.5 A Stored XSS vulnerability has been found in the administration page of the WTI Like Post plugin through 1.4.5 for WordP… wordfence
21dbe11c-8c9f-4b4c-98ef-3ba6eb5bb686
< 2.0.0
MEDIUM 5.5 The Universal Star Rating plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘usrCustomImagesFo… wordfence
21ae9136-a60c-483d-bdf4-b0c55796560d MEDIUM 5.5 The Content Repeater plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versi… wordfence
211aa83e-e97b-4fd7-8cfe-308ac698c17e
< 1.2.7
MEDIUM 5.5 The Search Exclude plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘the_title’ parameter i… wordfence
20deedff-8980-4ac2-a74e-c52cfe57e839
< 2.1.8
MEDIUM 5.5 An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php sale_c… wordfence
202c14d0-9207-47cb-9410-ca4c70d7b6d2
< 1.15.2
MEDIUM 5.5 The Google Tag Manager for WordPress (GTM4WP) plugin is vulnerable to Stored Cross-Site Scripting due to insufficient es… wordfence
1fe961c5-de2b-4494-9d89-6bcc7f6d8cd9 MEDIUM 5.5 The AgentEasy Properties plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
1f99a653-0ba2-48bc-a5be-a7e9ee10b5bd
< 7.0.0
MEDIUM 5.5 The Cache control by Cacholong plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
1f95bd2d-c835-4824-b241-f645b4a8fdb2
< 3.3.3
MEDIUM 5.5 Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin before 3.3.3 for W… wordfence
1f4b0be8-d2d7-4198-98a4-bb59561ff92e
< 3.9.3
MEDIUM 5.5 The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Se… wordfence
1f13a1c9-db26-4243-b8ee-f25eac51afa2 MEDIUM 5.5 The Font Awesome 4 Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in … wordfence
1eeea385-734c-4403-8886-e3ad6dc47140
< 1.2.13
MEDIUM 5.5 The Fast Flow WordPress plugin is vulnerable to stored Cross-Site scripting in versions up to, and including, 1.2.12, vi… wordfence
1ec207cd-cae5-4950-bbc8-d28f108b4ae7
< 3.2.7
MEDIUM 5.5 The Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) plugin for WordPress is vulnera… wordfence
1e9506bd-10a6-40ab-8162-cf4fad9cb882
< 1.6.7
MEDIUM 5.5 The Coming Soon, Under Construction & Maintenance Mode By Dazzler WordPress plugin before 1.6.7 does not sanitise or esc… wordfence
1e4c655c-9cdf-4106-9cf5-fc153de12d14
< 2212
MEDIUM 5.5 The Table of Contents Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' and 'label'… wordfence
1e2c40ea-5d0a-4f1c-99e8-ef0b54bbd20a
< 1.4.9
MEDIUM 5.5 The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in version… wordfence
1e25a0df-c548-45d0-8672-c35fbc71e0c3
< 4.3.3
MEDIUM 5.5 The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise and escape some of its settings, which could allow… wordfence
1e0fd85a-2164-4b83-822e-845662591a78
< 4.1
MEDIUM 5.5 The Get Custom Field Values plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin widget in v… wordfence
1d7d9521-4814-411d-859f-c7645551d3c5 MEDIUM 5.5 The 2kb Amazon Affiliates Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
1d7d8e85-c9cb-4fa5-9632-61f33048838d
< 1.1.19
MEDIUM 5.5 An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi… wordfence
1c6f7733-8c6d-487c-91e7-cc7df90cb962 MEDIUM 5.5 The AI Preloader plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0… wordfence
1c24a03a-95d8-4354-bb26-8575d70f2253
< 1.1.19
MEDIUM 5.5 An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi… wordfence
1c051bfd-2754-4faf-8062-91752555166c
< 3.6.5
MEDIUM 5.5 The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Suggest Terms Title field in ver… wordfence
1b8ef792-c2a8-4fc5-bee7-4de3b6b007c9
< 4.2.6
MEDIUM 5.5 The All in One SEO Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and includin… wordfence
← Prev 1047 1048 1049 1050 1051 1052 1053 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top