πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1265 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3e76c4b3-af77-4c02-a923-f04a360fa6e0
< 1.3.5
MEDIUM 4.8 The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which co… wordfence
3e2af005-0bc2-445c-956a-ef6139abfee4
< 3.3.2
MEDIUM 4.8 The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload … wordfence
3d39ae72-7d45-4ca9-9de1-8532ec5e043d
< 1.15.14
MEDIUM 4.8 The Asgaros Forums WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the na… wordfence
3d1f9fb7-fcb8-41ec-8c2f-0864e245f873
< 1.2.3
MEDIUM 4.8 The WP Downgrade WordPress plugin before 1.2.3 only perform client side validation of its "WordPress Target Version" set… wordfence
371fef9c-1f32-4a21-b4f4-1fc364ade5a4
< 1.3.56
MEDIUM 4.8 The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fiel… wordfence
33df558a-da81-46e0-bef9-ddb2bb90a5c5
< 2.0.1
MEDIUM 4.8 The Mark Posts WordPress plugin before 2.0.1 does not escape new markers, allowing high privilege users such as admin to… wordfence
2fa62862-5b98-4864-9bf1-4e05deedeb9d
< 2.3.3
MEDIUM 4.8 Multiple Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerabilities in Adam Skaat's Countdown & Clock … wordfence
2f7d7ceb-b6f0-4b63-93f7-632c13a6b496 MEDIUM 4.8 The Slideshow WordPress plugin through 2.3.1 does not sanitize and escape some of its default slideshow settings, which … wordfence
2e889182-f02f-4b6b-bb98-357fadae3dc1
< 3.0.16
MEDIUM 4.8 Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (… wordfence
2e10e550-735f-4bef-8e58-bcb79c51a5a6
< 1.6.57
MEDIUM 4.8 The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library β€” Shared Files … wordfence
2d853bd5-4caa-4b90-a9a6-929fb18b9337
< 3.7.16
MEDIUM 4.8 Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress… wordfence
2bf29d3d-98eb-40a7-88af-32b48e437572
< 2.3.5
MEDIUM 4.8 The Request a Quote WordPress plugin before 2.3.5 does not sanitise, validate or escape some of its settings in the admi… wordfence
2b346ae7-e3aa-4728-8dd9-e77fc388576e
< 1.1.6
MEDIUM 4.8 The Simple Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'datefilter' parameter fou… wordfence
2a37a0e5-2db5-49fb-8b00-1b820192f1af
< 2.4
MEDIUM 4.8 The Interactive Medical Drawing of Human Body WordPress plugin before 2.4 does not sanitise and escape the Link field, a… wordfence
29d962c0-31dc-4320-a9ce-3ed71d4f9943
< 7.1
MEDIUM 4.8 The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 7.1 did not sanitise the Redirect From and R… wordfence
28cb1a04-5129-430a-850e-c410e95d7b87
< 1.4
MEDIUM 4.8 The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, … wordfence
28bdf97b-86e7-4d4b-a3e4-6624e9858a93
< 1.3.1
MEDIUM 4.8 The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputti… wordfence
217b4ed7-90d3-4871-b034-7e1b324dc6a2
< 2.4.7
MEDIUM 4.8 The WP Contact Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the settings of sliders in v… wordfence
1f862575-afd8-4e38-8780-40e86ad9b5da
< 6.0.12
MEDIUM 4.8 The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some … wordfence
1e07562d-ab3a-47bc-9bb1-b952f769f5e5
< 1.0.0
MEDIUM 4.8 The Quotes llama WordPress plugin through 0.7 does not sanitise and escape Quotes, which could allow high privilege user… wordfence
1d7860bf-3f3d-4bd2-82b0-7bb94d00ff30
< 1.3.2
MEDIUM 4.8 The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created But… wordfence
1bf805fc-4b27-47c4-b24e-79158cffaac4
< 2021.18
MEDIUM 4.8 The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of i… wordfence
1abdc53b-7abe-422b-aeea-5bf31733bdad MEDIUM 4.8 The toggle-the-title (aka Toggle The Title) plugin 1.4 for WordPress has XSS via the wp-admin/admin-ajax.php?action=upda… wordfence
18afd787-2b1f-452c-90d8-75e0df9322fa
< 1.7.3
MEDIUM 4.8 The Twitter Bootstrap Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_cache_locatio… wordfence
188d812c-2955-4b0c-ae1c-b42c0f60b73b
< 6.5.2
MEDIUM 4.8 The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to Server-Side Requ… wordfence
← Prev 1262 1263 1264 1265 1266 1267 1268 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top