πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1266 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
171ee69a-d0d6-4d1e-b477-4d285be918f4
< .52.5
MEDIUM 4.8 In the admin/db-backup-security/db-backup-security.php page in the BulletProof Security plugin before .52.5 for WordPres… wordfence
15aba6ee-8345-401d-adf9-3fde0f5169bc
< 2.5.5
MEDIUM 4.8 The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before out… wordfence
15705cf2-f396-4b19-b58a-144b000f61e5
< 2.8.5
MEDIUM 4.8 Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Premio Chaty (WordPress plu… wordfence
14b334ee-ab3b-4b18-a776-c0831c4ff855
< 4.0.6
MEDIUM 4.8 Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress… wordfence
1212dfc7-41d4-4c16-960a-7afc882ec4db
< 1.0.2
MEDIUM 4.8 The Booking.com Product Helper WordPress plugin before 1.0.2 does not sanitize and escape Product Code when creating Pro… wordfence
11401ad7-6064-475c-92f6-ce72a56e9a83
< 1.8.9
MEDIUM 4.8 The Cookie Bar WordPress plugin through 1.8.8 doesn't properly sanitise the Cookie Bar Message setting, which could allo… wordfence
1072ad88-5760-4f2a-82b3-d515d6f73e52
< 3.6.8
MEDIUM 4.8 The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip… wordfence
0d3fa716-6f11-428c-b2da-2bb768a92fe0
< 4.6
MEDIUM 4.8 The WP BrowserUpdate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple parameters in ve… wordfence
0d00e477-8e01-4144-86e6-f1cc00fb1d0a
< 2.0.9
MEDIUM 4.8 The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The… wordfence
0b90503b-6186-48b5-a85a-3602f318872e MEDIUM 4.8 A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote at… wordfence
0992ac60-14c6-4432-bd6e-c11c6a7bf603
< 1.4.4
MEDIUM 4.8 The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s… wordfence
0987f9a5-eb11-4756-a09a-26dc66a8c690
< 1.6.59
MEDIUM 4.8 The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, a… wordfence
083d368c-ba38-433a-b499-c00d205bd331
< 1.6.13
MEDIUM 4.8 The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not sani… wordfence
04676263-cdad-40cd-bb54-61beb727e09d
< 0.16.18
MEDIUM 4.8 The AnWP Football Leagues plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 0.16… wordfence
03d02297-0cc6-4935-b282-9b95d8292954 MEDIUM 4.8 The WP Dialog WordPress plugin through 1.2.5.5 does not sanitise and escape some of its settings before outputting them … wordfence
03c8ec0a-f75f-450f-86e7-a18dfbae9461
< 2.1.1
MEDIUM 4.8 The Twitch Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜swti_options_player[swti_… wordfence
006544c9-09ed-4cda-a903-4e3959fdb676
< 1.3.35
MEDIUM 4.8 Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php … wordfence
ffb2ade3-d5ce-4459-ab83-e28cd4c84922
< 2.27.7
MEDIUM 4.7 The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Hig… wordfence
fa49346c-726e-41f9-8a74-adaa4a8fa5d9
< 7.6.9
MEDIUM 4.7 The Newsletter plugin for WordPress may be vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI'] … wordfence
f6d6b82d-574d-4a56-9aef-42343c4b7c43
< 3.8.16
MEDIUM 4.7 The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Re… wordfence
f668c3cd-bf64-4e95-8d75-70e4f12cabce
< 7.1.1
MEDIUM 4.7 The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPre… wordfence
f2b5213d-fdc5-4c98-9a05-15d83bd7308f
< 21.2.9
MEDIUM 4.7 The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress plugin … wordfence
f28feb11-7e28-4b97-b529-f6d266c3e534
< 5.5.5
MEDIUM 4.7 The Formidable Form Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and inc… wordfence
ef6b36a2-c18a-403a-aa0b-5d3e3ef1ca90
< 3.5.4
MEDIUM 4.7 The Easy Property Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
e7819dbf-fbcc-4dca-8300-b75ec096c541
< 7.1.14
MEDIUM 4.7 Wordfence before 7.1.14 was vulnerable in certain unusual configurations to Reflected Cross-Site Scripting, as well as f… wordfence
← Prev 1263 1264 1265 1266 1267 1268 1269 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top