🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1054 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
051a987a-944a-4898-872b-0456f0f59b27
< 6.5
MEDIUM 5.5 The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all v… wordfence
04e0b17e-efab-4b08-8c8a-93e3e4baffaa
< 3.7.31
MEDIUM 5.5 WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, po… wordfence
04aa7307-03c6-42f9-8219-fb6002c85050
< 4.1.1
MEDIUM 5.5 The Culture Object plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4… wordfence
045717f4-0e31-41f8-b0c3-8118c768b648
< 1.21
MEDIUM 5.5 The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own… wordfence
043263a1-ce87-45a2-83ee-4b826c7ffd7d
< 1.2.56
MEDIUM 5.5 The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all… wordfence
03cd1f6e-2400-44e7-b2b0-32c9890e1c1b
< 1.8.0
MEDIUM 5.5 The Custom Product Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
03a1724c-8fea-4e9f-a4a1-9de236e1f15a MEDIUM 5.5 The Export Users Data Distinct plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3… wordfence
03725477-7d7b-4ec9-8b9f-5ce9f8905243
< 3.4.7
MEDIUM 5.5 The Jetpack Boost – Website Speed, Performance and Critical CSS plugin for WordPress is vulnerable to Server-Side Requ… wordfence
0306c785-0dc3-44fb-a3cc-9afb5ab81651
< 1.5.13
MEDIUM 5.5 The WP Admin UI Customize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘footer text’ pa… wordfence
028a90c7-ded7-45ad-90ea-9f1a7d3743a0
< 1.1.7
MEDIUM 5.5 The Conversational Forms for ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via a form name in versi… wordfence
0252d07a-cf84-479d-a71b-a9b13a9765d5
< 1.90
MEDIUM 5.5 The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_da… wordfence
02319fc2-8a7e-4b3e-8711-724dcff7a233
< 8.8.5
MEDIUM 5.5 The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
012e7aed-04d9-4795-9ea9-40dd72fa612f MEDIUM 5.5 The Skimlinks Affiliate Marketing Tool plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions… wordfence
0016c624-9c0c-4157-8597-8b374dff7f14
< 7.3
MEDIUM 5.5 The WP Socializer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘misc_additional_css’ pa… wordfence
0004db27-9ea6-4387-ab1d-b95558784ed9
< 1.38
MEDIUM 5.5 The We’re Open! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its setting parameter… wordfence
ff937860-c4e0-4172-9f0f-d66578fa7203
< 2.0.46
MEDIUM 5.4 The Easy Table of Contents plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due … wordfence
ff7e7539-6a09-461a-a9a7-33630c396f1a
< 1.0.4
MEDIUM 5.4 The Auto YouTube Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
fec9a7a6-c515-4b43-8efc-9b3c86f0fd4b
< 7.9.8
MEDIUM 5.4 The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File upl… wordfence
fe25ac93-c3b6-49db-b36c-b31e9cce242c
< 11.12.7
MEDIUM 5.4 The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Server-Side Request Forgery in all ver… wordfence
fe14b92b-1784-4083-9b9f-23d7f69a3215
< 2.1.13
MEDIUM 5.4 The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… wordfence
fdc57b06-bae9-49a3-84dd-f593705330e9
< 3.15.2
MEDIUM 5.4 The Avada (Fusion) Builder plugin for WordPress is vulnerable to Arbitrary WordPress Action Execution in all versions up… wordfence
fd9f1385-6457-4bc9-9c75-0fcd399a5956
< 6.1.11
MEDIUM 5.4 The Awesome Support plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an un… wordfence
fd5f370c-743f-41f1-80ab-7f0805cae38c MEDIUM 5.4 The Scheduler Widget plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i… wordfence
fd53b4e1-c6b7-4111-911a-04b14c7a9c4e
< 1.12.8
MEDIUM 5.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
fd3bf470-f966-454d-8df3-0dec4682e883
< 6.1.13
MEDIUM 5.4 The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to… wordfence
← Prev 1051 1052 1053 1054 1055 1056 1057 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top