🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1051 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1b85306d-ffb6-487d-a981-6fc04b27e751
< 1.8.18
MEDIUM 5.5 The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Me… wordfence
1a367b5a-cfba-41fa-9243-256a391a4661 MEDIUM 5.5 The Contact Bank plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0… wordfence
19e9735c-ddaa-4b38-ad21-b2f13c0d4461 MEDIUM 5.5 The WP-Spreadplugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
198e8f56-5354-4e5d-af51-54e95d34e25c
< 3.0.5
MEDIUM 5.5 The Recently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘upload_thumb_src’ parameter … wordfence
1978fd4f-f130-4e72-85df-24a6f9aebfe2 MEDIUM 5.5 The Real Estate Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions… wordfence
185c9962-aa4a-4049-acdb-3f439c420c5a
< 1.15.17
MEDIUM 5.5 The Photo Gallery by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… wordfence
184c07ad-e0d9-47c9-9582-828947cc97f9
< 2.9.18
MEDIUM 5.5 The WP STAGING plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.1… wordfence
1832b11a-0706-438a-9a25-d384ac49d2bf
< 1.5.5
MEDIUM 5.5 The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute … wordfence
17e4376e-2b77-4c86-b962-ea4d7d8f534d MEDIUM 5.5 The Inspirational Quote Rotator WordPress plugin through 1.0.0 does not sanitize and escape some of its quote fields whe… wordfence
179821bb-5b0d-4c41-a410-db433987a870
< 3.1.8
MEDIUM 5.5 The User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin bef… wordfence
16e63535-28bc-4a3d-a201-4216dc786d98
< 4.0.2
MEDIUM 5.5 The Poll Maker WordPress plugin before 4.0.2 does not sanitise and escape some settings, which could allow high privileg… wordfence
16c70597-32a0-4771-877b-c57cf7550ee7
< 4.16
MEDIUM 5.5 The AFS Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… wordfence
16c4c9ff-2d57-4cba-adad-72d012bd12f7
< 4.7.10
MEDIUM 5.5 The Button contact VR plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
16a285b1-7a20-455f-8f74-2e468dd436d3
< 2.12.5
MEDIUM 5.5 The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
168ff5ec-52f2-4234-aee4-6d460b72d6c5
< 1.6.2
MEDIUM 5.5 The Auto Hide Admin Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the keyboard shortcode val… wordfence
1641758d-a7d7-4677-98a6-cb4a6fea0c63 MEDIUM 5.5 The PCA Predict plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blockip’ parameter in ver… wordfence
16102d4c-86d6-471e-b787-54e4bc14b5a2
< 3.7.15
MEDIUM 5.5 The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspeci… wordfence
160dd5b9-ed70-4617-9bff-59e33f9ea2d8
< 2.2.11
MEDIUM 5.5 The Carousel Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url view parameter in all … wordfence
15f03dc6-2881-4f70-925c-80ef9ce40be2
< 4.4.59
MEDIUM 5.5 The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high pri… wordfence
15ec3b68-0461-4b99-81e1-0d776b97a4eb MEDIUM 5.5 The EU Cookie Law plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in version… wordfence
15e86f80-b18c-42f7-bc41-6a3112cbb162
< 1.2.32
MEDIUM 5.5 The Form Builder CP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
15b9d69c-012d-4a28-b8b1-15e6dd22979e
< 3.6.8
MEDIUM 5.5 The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which… wordfence
156e64f2-87a4-40a0-bac8-3dc1f702b0a1
< 5.9.7.2
MEDIUM 5.5 The Events Manager plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 5.9.7.1 through… wordfence
13f33422-13ba-4696-a473-cf8ca00d4b0c
< 4.7.8
MEDIUM 5.5 The Molongui plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.7 d… wordfence
13c607d9-a8fe-4a03-972c-d0c1b752c7d8
< 1.2.5
MEDIUM 5.5 The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit… wordfence
← Prev 1048 1049 1050 1051 1052 1053 1054 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top