πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1260 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f2fee7aa-5289-4bf0-b175-5a64b16fdd40
< 1.4.3
MEDIUM 4.8 The Booking.com Banner Creator WordPress plugin before 1.4.3 does not properly sanitize inputs when creating banners, wh… wordfence
f2f4313a-568e-4ee2-b283-cd7bb62b75fa
< 3.2.4
MEDIUM 4.8 The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outp… wordfence
f20aff55-f9c9-42f7-9c7b-3f4a709f4a60
< 2.6.5
MEDIUM 4.8 The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript exe… wordfence
f15d39ba-9211-4d35-8252-20d53c6bc249
< 1.68.7
MEDIUM 4.8 Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plug… wordfence
f09584f9-7ea3-4cfb-bbdf-7ca241e64bb1
< 3.1.3
MEDIUM 4.8 Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) vulnerability in Fatcat Apps Easy Pricing Tables… wordfence
f01e9908-c4d7-4eaf-8bba-4f5da7fa7703
< 4.5.2
MEDIUM 4.8 The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to maliciou… wordfence
efd18739-3cd1-486c-9587-8deba5a0940e MEDIUM 4.8 The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_title' parameter in all … wordfence
eeae71a6-53b2-4eab-82c0-d23cff3f0f7c
< 2.1.2
MEDIUM 4.8 The WP GDPR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button Text setting in versions up… wordfence
ee4a9dc6-fc0b-4bab-9511-fa0a713800ff MEDIUM 4.8 The HPB Dashboard WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow hi… wordfence
edcc51f8-bf79-453a-aa4d-5d1d491316eb
< 2.0.7
MEDIUM 4.8 The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, whic… wordfence
eaf0d324-bf2c-4da7-b2ab-f53f7b7881f2
< 3.6.10
MEDIUM 4.8 The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field labels in versi… wordfence
e97ed28c-b4a2-47ee-8fbe-7c995fa102cb
< 3.26.2
MEDIUM 4.8 The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
e6a9ae9e-17f2-4fcb-8428-f6bf1a500bc4
< 1.8.18
MEDIUM 4.8 The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter. Please note this requires administrat… wordfence
e6838714-4128-47c5-b596-91cfc68abade
< 1.9.5
MEDIUM 4.8 The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attri… wordfence
e6650eb7-143f-4c8f-b18f-056fc82972fc
< 1.4.9
MEDIUM 4.8 The Product Reviews Import Export for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to,… wordfence
e608c75f-dd84-4921-ae61-2bfa5cd717a5 MEDIUM 4.8 The BannerMan WordPress plugin through 0.2.4 does not sanitize or escape its settings, which could allow high-privileged… wordfence
e5748252-d02a-463b-abb4-537144ccd608
< 1.16.45
MEDIUM 4.8 The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high priv… wordfence
e52f799e-9174-45a2-9ed6-7aedb26b36bd
< 6.0.14
MEDIUM 4.8 The awesome-support plugin 6.0.13 and below for WordPress allows XSS via the post_title parameter. wordfence
e404d689-f0b5-43cc-b366-b7d6a44a9dcc
< 6.2.7
MEDIUM 4.8 Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in MaxGalleria Wor… wordfence
e3702936-9ae2-4efb-bdfe-9e1dfceb246b
< 0.4
MEDIUM 4.8 The Protect uploads plugin for WordPress failed to use a capability check and leaked the nonce necessary to save changes… wordfence
e0df0a4e-282e-483a-8d5e-a192620ed2d2 MEDIUM 4.8 The Call&Book Mobile Bar WordPress plugin through 1.2.2 does not sanitize and escape some of its settings, which could a… wordfence
df2674c9-da77-412c-a812-f1749f54d04b
< 4.5.0
MEDIUM 4.8 The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
dde57a98-06d5-4a3c-b100-170e9c339908
< 5.0.07
MEDIUM 4.8 The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not san… wordfence
dab3786b-1f8e-428c-afee-afd3e43f40ba MEDIUM 4.8 The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow hi… wordfence
d6286cda-c5b1-4923-bbf3-9f5b56973d23 MEDIUM 4.8 The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which c… wordfence
← Prev 1257 1258 1259 1260 1261 1262 1263 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top