πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1262 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b0d8a530-53fd-4e2f-aa57-d75c89dc2a51
< 4.19.2
MEDIUM 4.8 The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, a… wordfence
afbf555a-1b70-4966-9b05-46e9de04e660
< 7.3.2
MEDIUM 4.8 The Comments - wpDiscuz WordPress plugin through 7.3.0 does not properly sanitize or escape the Follow and Unfollow mess… wordfence
ae3d33dd-2591-4c4e-9769-77575e57ac49
< 1.1.5
MEDIUM 4.8 The Video Gallery WordPress plugin before 1.1.5 does not escape the Title and Description of the videos in a gallery bef… wordfence
ade346fc-d158-4485-85a8-d14d5e059554
< 2.2.3
MEDIUM 4.8 The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
ab3033c5-95c3-44eb-8602-410288fc423f
< 1.9.7
MEDIUM 4.8 The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[enabled_languages][en] or wpglobus_option[enable… wordfence
a9ed9a77-5a51-4664-a8a5-579824f8eae7
< 1.2.8
MEDIUM 4.8 The Shop Page WP WordPress plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, … wordfence
a8f91e58-942c-417f-ad82-5bd99ab5e81a MEDIUM 4.8 A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote at… wordfence
a7e58c6d-5b95-4b22-a7fc-e5e8324ed52a MEDIUM 4.8 The Easily Generate Rest API Url WordPress plugin through 1.0.0 does not escape some of its settings, allowing high priv… wordfence
a66c2e1e-fd59-424b-bd11-0991a5c32dce MEDIUM 4.8 The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to… wordfence
a333d5b4-cedf-40ac-8da9-f4965d2a397a
< 8.4.4
MEDIUM 4.8 The NEX-Forms - Ultimate Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form names p… wordfence
a27da737-d925-471f-b0e0-25bc27a95714
< 1.68.7
MEDIUM 4.8 Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager WordPress plugin (vers… wordfence
a1eec01c-7f54-4e90-a943-c50b8ab79b22
< 1.7.4
MEDIUM 4.8 The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and G… wordfence
9ec307de-600c-4fb2-b474-db9b674d4ead MEDIUM 4.8 The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
9d9cf724-9ae7-4414-88d1-10640491df34
< 2.1.3
MEDIUM 4.8 The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several CDN settings in version… wordfence
9d68ab8b-38c8-47aa-8b69-8cebe0a8d24e
< 1.15.4
MEDIUM 4.8 The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high… wordfence
9bf8485b-a363-44a3-93c7-a6fba034b48f
< 1.47
MEDIUM 4.8 The SrbTransLatin plugin 1.46 for WordPress has XSS via an srbtranslatoptions action to wp-admin/options-general.php wit… wordfence
9b8aef59-8d7a-4ffd-9619-9684a6e51e5a
< 3.1.3
MEDIUM 4.8 The Rencontre – Dating Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters f… wordfence
97e9037e-7d7a-4dad-bce1-0211822c04c1
< 1.6.61
MEDIUM 4.8 The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which c… wordfence
96b58c2c-f292-4a48-bd1e-c33cf464c1ce
< 1.3.25
MEDIUM 4.8 The Contact Form Email WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validatio… wordfence
959ece75-b7a6-4729-abe8-1df9398d95f4 MEDIUM 4.8 The Social Hashtags plugin for WordPress is vulnerable to Cross-Site Scripting via the new post title field in versions … wordfence
94d2eaed-048b-40b6-9880-fa32fbb66f92
< 5.9.5
MEDIUM 4.8 The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin… wordfence
92c16bb5-b52c-4453-9121-0c9d056a0cdb
< 1.53
MEDIUM 4.8 The Mortgage Calculators WP WordPress plugin before 1.53 does not implement any sanitisation on the color setting of the… wordfence
90d203b1-9426-4eff-b566-02c8a1c6adfa
< 1.18.1
MEDIUM 4.8 The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,… wordfence
90cd3722-c3cb-4ac3-871d-cacda49be294
< 1.9.7
MEDIUM 4.8 The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][post] parameter to wp-admin/options.p… wordfence
8df4f144-0bf3-457f-8014-f603f7179044
< 1.7.48
MEDIUM 4.8 The AddToAny Share Buttons WordPress plugin before 1.7.48 does not escape its Image URL button setting, which could lead… wordfence
← Prev 1259 1260 1261 1262 1263 1264 1265 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top