🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1052 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
13874012-09b4-4e6a-a364-07321dbd0167 MEDIUM 5.5 The Very Simple Breadcrumb WordPress plugin through 1.0 does not sanitise and escape its settings, allowing high privile… wordfence
12d84de4-d97e-40cc-9805-fc9b7de8fa21
< 1.1
MEDIUM 5.5 The Interactive SVG Image Map Builder for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in v… wordfence
128f0e5e-96c7-474e-bfc9-ea18536b4a54
< 2.1.0
MEDIUM 5.5 The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layouts’ parameter in vers… wordfence
1254e0ad-852e-4fd4-8317-61bfbbc9f737
< 2.56
MEDIUM 5.5 The External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
11653fa1-c6f5-4bcc-81d2-dd469300b40a
< 1.10
MEDIUM 5.5 Virtual Robots.txt before 1.10 does not block HTML tags in the robots.txt field. wordfence
10ef8475-4ec5-4412-97f6-3abdb4442b92 MEDIUM 5.5 The alfred24 Click & Collect plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
10d861c2-8ebf-4ba8-a493-0ab3aa43aa76
< 2.1.23
MEDIUM 5.5 In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for … wordfence
10a0abd6-1905-4a90-8488-29d44df7aeb9
< 7.0
MEDIUM 5.5 The All-in-One WP Migration plugin for WordPress is vulnerable to Cross-Site Scripting due to the fact that the backup d… wordfence
0ff49f18-d6a6-46c9-a0be-e80dfe407992
< 1.1.8
MEDIUM 5.5 The Ads.txt & App-ads.txt Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ver… wordfence
0fdc2dac-b3ea-40bd-987b-e6c47e74aefc
< 4.1.11
MEDIUM 5.5 The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to Server-Side Request Fo… wordfence
0f3c3629-b7a9-4f83-a821-64119ed662ce
< 1.2.5
MEDIUM 5.5 The Themify Portfolio Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
0f01c9c8-acd4-44c0-8866-a0a819828006
< 2.1
MEDIUM 5.5 The All 404 Redirect to Homepage & Broken images Redirection plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
0ec90144-bfd8-4840-8b0f-73340386b7d5
< 1.9.9
MEDIUM 5.5 The Donations via PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting when saving settings in versi… wordfence
0ebaf76d-b659-41d2-8c66-4d6204678222
< 1.5.0
MEDIUM 5.5 The Really Simple Under Construction Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
0e6616d0-0690-4bf4-9228-33679b926b90 MEDIUM 5.5 The Image Hover Effects Css3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
0e5674e2-593a-4f53-bb03-9184eccc3244
< 9.13
MEDIUM 5.5 The WP Spell Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versio… wordfence
0e38b567-9567-4b08-8fab-3971547394b0 MEDIUM 5.5 Directory traversal vulnerability in wp-db-backup.php in the Skippy WP-DB-Backup legacy plugin for WordPress 1.7 and ear… wordfence
0de0e5d5-7023-4026-ad82-3c2443569326
< 1.0.4
MEDIUM 5.5 The Accessibility plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
0dda8e76-22aa-400b-b4c1-b24e6e1141ac MEDIUM 5.5 The Google Maps Anywhere plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters from t… wordfence
0d627ee7-1175-4621-a477-1e9ec2d05eee MEDIUM 5.5 The Reusable Text Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text-blocks' shortcode i… wordfence
0d4c5ff9-d4aa-4270-b00b-41353b32c8e5 MEDIUM 5.5 The 404 to Start plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters i… wordfence
0d3aa440-29a8-47cd-98f4-cf1cbdf92f66
< 9.7.8
MEDIUM 5.5 The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Cust… wordfence
0cfdb6de-41f8-4bea-a017-5708fceee762
< 2.1.1
MEDIUM 5.5 The Social Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ssb_share_content_ico… wordfence
0c80cbad-39ea-4f75-a025-6b9667560845 MEDIUM 5.5 The Float to Top Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters such as… wordfence
0c788d06-6a80-4e34-92bb-b87f21916810
< 1.10.20
MEDIUM 5.5 The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table se… wordfence
← Prev 1049 1050 1051 1052 1053 1054 1055 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top