πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1263 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8a5bf903-9da0-46fd-8134-3abe8e97e3b4
< 2.10.4
MEDIUM 4.8 The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Ba… wordfence
8703c76b-89c6-438a-b953-03847d965096
< 3.5.8.2
MEDIUM 4.8 The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the f… wordfence
850f554f-abb5-4b9f-9b7b-67439abb1a31
< 2.1.17
MEDIUM 4.8 The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_f… wordfence
82173c1b-dce8-4713-87c7-2c54ba8cc02c MEDIUM 4.8 The User Registration, Login & Landing Pages WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insuff… wordfence
816ec7bd-dd0f-4c52-b73f-72cd25c410b2
< 2.0.3
MEDIUM 4.8 The Print-O-Matic WordPress plugin before 2.0.3 does not escape some of its settings before outputting them in attribute… wordfence
81141b8c-9677-4267-9026-33267e3135f5
< 4.7.0
MEDIUM 4.8 The iFlyChat WordPress plugin before 4.7.0 does not sanitise its APP ID setting before outputting it back in the page, l… wordfence
7ccf6945-6f18-410b-9f1a-6d52a3cdda1a
< 2.17.3
MEDIUM 4.8 The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute i… wordfence
7c84b432-4d33-47ad-8057-0bc831929879
< 1.2.3
MEDIUM 4.8 Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) in PlausibleHQ Plausible Analytics (WordPres… wordfence
7bde915d-092a-452b-a0e0-ce5c2ce203dc
< 4.1.1
MEDIUM 4.8 The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to unauthorized l… wordfence
76b11177-782a-4d9c-a974-4cb9ff55fa99
< 1.9.7
MEDIUM 4.8 The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[more_languages] parameter to wp-admin/options.ph… wordfence
73c3dfc7-58de-4b24-ad91-0f8040d1f75e
< 4.3.21
MEDIUM 4.8 Authenticated (admin user role) Stored Cross-Site Scripting (XSS) in WP-Appbox (WordPress plugin) <= 4.3.20. wordfence
736cb9a4-bd43-4aaa-a918-d15ca3ff4dbf
< 5.4.1
MEDIUM 4.8 The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privile… wordfence
728cec6e-a246-4e2c-a906-750518bae0a4
< 3.0.5
MEDIUM 4.8 The Fathom Analytics WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation … wordfence
6f7e0aa7-8834-4ff1-9ced-5d740936c721
< 6.8.0
MEDIUM 4.8 The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, all… wordfence
6d7f9291-5a57-4aca-b18f-623bf07348a4
< 2.10.5
MEDIUM 4.8 The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section paramete… wordfence
6d564606-695e-4e8c-90de-1d55afc06103
< 1.5.67
MEDIUM 4.8 The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the … wordfence
6c31f7d3-1f2f-4ec5-802b-ec0b22087d43
< 3.1.23
MEDIUM 4.8 The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting th… wordfence
6bfc0128-a8ef-4bb9-b5c8-7003f270aa36
< 1.0.8
MEDIUM 4.8 The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its … wordfence
6b8ed659-0590-411f-9017-f695c9c2f322
< 7.3.2
MEDIUM 4.8 The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it … wordfence
674f75d7-83de-4d0b-80f2-ee83dd474728
< 2.2.45
MEDIUM 4.8 Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Ti… wordfence
64b49f24-db48-4199-9ce2-3ea70c68d6af
< 0.9.9.4
MEDIUM 4.8 The Recent Posts Widget Extended plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and inclu… wordfence
64338fc4-e8c9-4fa5-bb77-861fb5142286
< 4.1.8
MEDIUM 4.8 The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow … wordfence
63089b8f-0e0f-4951-9f8b-8b64d539b4c0
< 3.8.6
MEDIUM 4.8 The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versio… wordfence
606b9002-5f3a-49ef-9714-49eeac86f800
< 1.7.0
MEDIUM 4.8 The Cybersoldier WordPress plugin before 1.7.0 does not sanitise and escape the URL settings before outputting it in an … wordfence
5d432ea5-9ffd-43da-8988-6dd77b907655
< 2.5.2
MEDIUM 4.8 The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin … wordfence
← Prev 1260 1261 1262 1263 1264 1265 1266 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top