ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1053 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0c157d70-1d4d-482e-8996-bc047a801681 MEDIUM 5.5 The Event Timeline WordPress plugin through 1.1.6 does not sanitize and escape Timeline Text, which could allow high-pri… wordfence
0bba9e06-4c5b-43e4-a51b-af57c5390c8a
< 2.1.28
MEDIUM 5.5 Multiple Authenticated (administrator or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in TMS-… wordfence
0b95749b-c522-42cd-aa99-36bdf15541c3 MEDIUM 5.5 The Eventify plugin for WordPress is vulnerable to Stored Cross-Site Scripting parameter in versions up to, and includi… wordfence
0b7da6f7-d486-44e5-9eeb-21feb119a48b MEDIUM 5.5 The Add Shortcodes Actions And Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
0b458e27-331b-4ae2-ade8-8b14aeffb1e2 MEDIUM 5.5 The WP Super Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting parameter in versions up to, and in… wordfence
0abf9705-2716-403f-9348-e43a8d8fb1d2
< 7.2.4
MEDIUM 5.5 The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_produ… wordfence
0a73d326-cd27-4719-8c26-3aa5dce837c0
< 3.2.16
MEDIUM 5.5 The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputt… wordfence
09ee6179-8071-4628-9d2b-dfbb32ef1804
< 1.0.8
MEDIUM 5.5 The Relevant Related Posts plugin up to and including version 1.0.7 for WordPress is vulnerable to stored cross-site scr… wordfence
09952b56-a064-46f9-b037-be86cf6df781
< 1.4.12
MEDIUM 5.5 The Cimatti Contact Forms plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1… wordfence
09613e4a-0dbe-430a-ab75-725038218803 MEDIUM 5.5 The Any Hostname WordPress plugin through 1.0.6 does not sanitise or escape its "Allowed hosts" setting, leading to an a… wordfence
095bee95-d3a7-4203-96eb-90f1f0eab84f
< 1.0.77.32
MEDIUM 5.5 Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – A… wordfence
094c0952-4e28-4ed0-80ae-14fcf10cf2e1
< 3.1.2
MEDIUM 5.5 The Survey Maker – Best WordPress Survey Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
0933ea77-2de0-4cd5-a589-a4c1d474f119
< 2.1.0
MEDIUM 5.5 The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any parameters used in the 'rawdata… wordfence
09277f30-9b6a-4cc9-bc8c-09c360da917a
< 5.1.1
MEDIUM 5.5 The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privile… wordfence
09023fe2-52dd-43af-ae4f-1fb46654f305
< 2.13.1
MEDIUM 5.5 The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Server-Side Req… wordfence
08ffb478-7280-4fbc-bc5f-482c1348091e
< 3.4.5
MEDIUM 5.5 The Google Apps Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
082efb3c-dbe4-49b5-abec-da91f2d463eb
< 1.0.3
MEDIUM 5.5 The Opensea WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, like its "Referer address" … wordfence
07c0516b-ee3a-4a80-8db7-e6372bb294a1
< 5.8.23
MEDIUM 5.5 The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perfo… wordfence
0758e317-d67e-4767-bbaa-cfcbf86d4819
< 1.8
MEDIUM 5.5 The Smartarget Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
06905738-7e1c-4d1a-97d2-f68f978ad8ed
< 0.5.28
MEDIUM 5.5 The Duplicator plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.5.26 due t… wordfence
06511129-fb43-4ac1-9f5d-c637c9577293
< 2.0.3
MEDIUM 5.5 The Link Juice Keeper plugin for WordPress is vulnerable to stored cross-site scripting in versions up to, and including… wordfence
05fe1929-9e39-4b2f-a3fc-e692267d731b
< 4.3
MEDIUM 5.5 The DSGVO All in one for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dsdvo_customimp… wordfence
05ee4692-451b-4ff4-9bf0-8a16d39404ea
< 3.0.4
MEDIUM 5.5 The Top Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tpbr_message,tpbr_btn_text,tpbr_bt… wordfence
05dcfd2d-6488-4f82-b20b-4968e4a00796
< 1.3.1
MEDIUM 5.5 The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to… wordfence
0551a2ca-b920-4a60-9c16-0bb14fd63a23
< 8.0
MEDIUM 5.5 The wp-forecast plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions u… wordfence
← Prev 1050 1051 1052 1053 1054 1055 1056 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top