🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1264 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5c6f4890-8bc9-4ead-8d69-478fa51c2176 MEDIUM 4.8 The W-DALIL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$dalil_information’ parameter… wordfence
5b3081ff-9898-46a2-8e02-30cd83f4fbe4
< 6.4.3
MEDIUM 4.8 The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped… wordfence
5a563439-c1c2-4a19-b5f7-22ed7be87ad7
< 1.4
MEDIUM 4.8 The Smooth Scroll Page Up/Down Buttons WordPress plugin through 1.4 does not properly sanitise and validate its psb_posi… wordfence
59cdb3e3-06ca-4325-9dae-73ad3cdfd910
< 19.9.7
MEDIUM 4.8 The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
58bdd837-adae-4fa9-9ca3-00633a6a1ede
< 2.0.0
MEDIUM 4.8 The WPFront Notification Bar WordPress plugin before 2.0.0 does not sanitise or escape its Custom CSS setting, allowing … wordfence
586137a5-8758-400e-a66a-2382f8633578
< 1.10.1
MEDIUM 4.8 The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation … wordfence
56a362f3-dc4e-454d-9d94-9f4cb540d4b5
< 2.11.2.1
MEDIUM 4.8 The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end… wordfence
52af7568-061d-4352-b85c-11f9829bc8a5
< 1.7
MEDIUM 4.8 An issue was discovered in the dark-mode plugin 1.6 for WordPress. XSS exists via the wp-admin/profile.php dark_mode_sta… wordfence
50e373bd-4408-4406-a411-3284fa71e7ef
< 3.0.4
MEDIUM 4.8 The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege… wordfence
4dcc6225-b47a-4184-a2f3-1292e5abe1bd
< 3.1.21
MEDIUM 4.8 The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow… wordfence
4dbaeabb-2610-4b24-8c47-a04b073bd290
< 5.2.0
MEDIUM 4.8 The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Additional tax classes' field… wordfence
4d2d435f-d6ce-41bd-8a45-e252fb4ba419 MEDIUM 4.8 The GWD Connect plugin for WordPress is vulnerable to missing authorization to limited code execution in all versions up… wordfence
4bca364b-c8dc-4c32-a640-0e9f3155a40f MEDIUM 4.8 The Mimetic Books WordPress plugin through 0.2.13 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) in t… wordfence
4b3786d2-b1b5-4d96-9ef7-957909061186
< 2.1.4
MEDIUM 4.8 The WP-Paginate WordPress plugin before 2.1.4 does not sanitise and escape its preset settings, allowing high privilege … wordfence
4a515dc9-e6d6-4083-a3e8-c22307b120a8 MEDIUM 4.8 The Quiz Tool Lite WordPress plugin through 2.3.15 does not sanitize multiple input fields used when creating or managin… wordfence
49fc7174-9263-4158-8cdc-cd249179eb3b
< 2.0.44
MEDIUM 4.8 The WP Courses LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions before 2.0.44 due to i… wordfence
49ac9c7c-d457-4709-bc10-c3de8b4f097a
< 5.0.13
MEDIUM 4.8 The addthis plugin before 5.0.13 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=add… wordfence
498087da-3887-475a-9796-676ee1d1fb99
< 2.12.0
MEDIUM 4.8 The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level… wordfence
4489d26b-dcdc-475c-b1e1-3626cc75ae75
< 4.1.3.1
MEDIUM 4.8 The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course setting… wordfence
43f6a5c2-3de0-4990-89ad-64e5d866345a MEDIUM 4.8 The Sociable WordPress plugin through 4.3.4.1 does not sanitise or escape some of its settings before outputting them in… wordfence
427c29e6-9bbe-4094-a2a2-46945525f5b3
< 1.5.6
MEDIUM 4.8 The Ad Inserter plugin for WordPress is vulnerable to Cross-Site Scripting via the 'ai-active-tab' parameter in versions… wordfence
4107199d-e3c7-4379-b39d-1868de7d777b
< 2.2.3
MEDIUM 4.8 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
40e61b9f-2350-410e-bb3d-59329ac08658
< 4.0.72
MEDIUM 4.8 The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to ma… wordfence
3f8af7fd-5800-4179-849e-a7ffaf8c3ad4
< 2.6.3
MEDIUM 4.8 The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users… wordfence
3eff7a6f-7098-4298-b399-91974b16fda2
< 1.35
MEDIUM 4.8 The ClickBank Affiliate Ads WordPress plugin through 1.20 does not escape its settings, allowing high privilege users to… wordfence
← Prev 1261 1262 1263 1264 1265 1266 1267 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top