πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1271 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ffa92cb6-7444-4794-81c1-264ff5a08fa5
< 2.3.3
MEDIUM 4.4 The Popup – Popup More Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
ff559912-8609-46e6-b64f-f05f5232276c
< 15.6
MEDIUM 4.4 The WP Google Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
fefab999-12e0-4866-a5a2-60f8faa64f89 MEDIUM 4.4 The Easy Admin Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up … wordfence
fed6bb3e-40f1-4d7a-b643-485f908cc816 MEDIUM 4.4 The clubmember plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
fed4dd54-7a7e-483b-a623-3cf3392572b8
< 1.19.0
MEDIUM 4.4 The HTTP Headers for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and in… wordfence
fec06875-f6b4-4e57-917f-e80ece3744e1 MEDIUM 4.4 The Better Follow Button for Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… wordfence
fea688c7-88d6-424b-90e2-f82eb37c5a0e
< 1.9.4
MEDIUM 4.4 The Maps Plugin using Google Maps for WordPress – WP Google Map plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
fe82e9d2-764b-49da-a062-c5fc7c876396
< 1.7.0
MEDIUM 4.4 The URL Shortify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to,… wordfence
fe3c897a-c3fb-4d1f-ad4c-c1bbb781a5aa
< 2.9.9.4.8
MEDIUM 4.4 The Pinpoint Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
fe2fcc3f-e7ce-4f9a-b9a9-e6cf9129aec9
< 2.7.2
MEDIUM 4.4 The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme – My Sticky… wordfence
fdf68c19-ee1b-4d0a-876b-c061763b39c3
< 3.3.203
MEDIUM 4.4 The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
fdf102bb-66ed-4c4d-b9b0-906f58ec9253 MEDIUM 4.4 The Recaptcha – wp plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
fdbd089d-1b7d-42e9-8f47-fec19a4dd7c4
< 1.9.4
MEDIUM 4.4 The Ultimate Under Construction plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
fd9ef610-a845-4fdf-a4ad-db073b1cc8bb MEDIUM 4.4 The Magento 2 WordPress Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
fd7415b1-846f-41ad-a19f-73d0cee3965f
< 4.6
MEDIUM 4.4 The Just Writing Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
fd683a80-2090-4f9b-8342-7cc76675067e
< 1.15.26
MEDIUM 4.4 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Store… wordfence
fd1c679b-43e0-4e3a-ae2d-f6ff8a657512
< 3.8.1
MEDIUM 4.4 The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
fd0f2802-3273-42e9-a219-911f143b905d
< 1.5.2
MEDIUM 4.4 The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… wordfence
fcf09793-1277-41a0-9ce4-b85b13721729 MEDIUM 4.4 The nuajik CDN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, a… wordfence
fcc218bf-2845-4d7f-8b93-e0fe9bc4bf79 MEDIUM 4.4 The Instant Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
fc4048a9-b69c-4f4c-8a30-e57bb057b00c
< 2.5.2
MEDIUM 4.4 The WP Discord Invite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio… wordfence
fc305c48-8337-42b7-ad61-61aea8018def
< 4.9.7
MEDIUM 4.4 The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions 4.8.6 through 4.9… wordfence
fc296c70-358e-4908-be49-5ffae83aca9b
< 4.3.5
MEDIUM 4.4 The Ninja Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions u… wordfence
fbef8738-d639-48a5-98b7-abf9a7e9fec1
< 3.0.0
MEDIUM 4.4 The TreePress – Easy Family Trees & Ancestor Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
fbd8fec7-c95a-4c03-ac0d-894a54906863 MEDIUM 4.4 The RSS Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜link_color’ parameter… wordfence
← Prev 1268 1269 1270 1271 1272 1273 1274 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top