πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1272 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fbba15aa-9d65-4cb8-867f-667af09ff826 MEDIUM 4.4 The Widget Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
fb9b8f3a-6f49-455d-99c6-cdf5671af49d
< 1.2.5
MEDIUM 4.4 The eRocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'share_text' value in versions up … wordfence
fb88e629-6811-4651-99b9-7394e4a787b6
< 1.1.9
MEDIUM 4.4 The Bit Assist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, a… wordfence
fb66f8f4-1800-41f8-bd67-70d89f612144 MEDIUM 4.4 The Mesa Mesa Reservation Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
fb28c526-67ae-441d-9964-5ac17b966687 MEDIUM 4.4 The Category Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag-image' parameter in al… wordfence
fb1cf9f1-7b87-4690-80db-0d4b3ccd98f9 MEDIUM 4.4 The Similar Posts – Best Related Posts Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknow… wordfence
fb1693c7-4c38-4723-868a-9f105dac1561
< 3.2.2
MEDIUM 4.4 The Save as Image Plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… wordfence
fae586f3-dc4b-45ee-83b2-cdaa0336fe07
< 2.6.1
MEDIUM 4.4 The WP Terms Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
facfa21a-4136-4161-ac39-8b18948ec073 MEDIUM 4.4 The CC Custom Taxonomy for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.… wordfence
fac4ae61-cfc6-4efc-9f57-58fa39e00f07
< 2.1.46
MEDIUM 4.4 The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio… wordfence
faaa7b98-d762-4e5e-9178-a419de2629c6
< 1.3.6
MEDIUM 4.4 The Ultimate Noindex Nofollow Tool II plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settin… wordfence
fa5ae08b-d85f-45aa-9617-ec629b8ec985
< 3.2.13
MEDIUM 4.4 The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i… wordfence
fa3819b1-8e7c-4e97-bac5-96d73d935845 MEDIUM 4.4 The oAuth Twitter Feed for Developers plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
fa2ed43b-cd8f-4d09-8576-d215c835a684
< 4.0.5
MEDIUM 4.4 The ARMember plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 d… wordfence
fa16605a-12bd-48a8-b9a9-db53bf3c2c39
< 2.2
MEDIUM 4.4 The Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image metadata in all versions … wordfence
f9fe2885-d9ef-4506-945a-69bdddf41718
< 3.4
MEDIUM 4.4 The WP Poll Maker – Best WordPress Poll Plugin for Voting Contest plugin for WordPress is vulnerable to Stored Cross-S… wordfence
f9b6e9a7-1ac5-45d0-83c3-a3f79935904a
< 1.53.2
MEDIUM 4.4 The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
f99b7b42-cebf-4382-834e-9d96d87f395e
< 1.167
MEDIUM 4.4 The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
f99622df-0bf3-4252-8bd3-f84c61fcd39a
< 1.5.6
MEDIUM 4.4 The HTML Forms – Simple WordPress Forms Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a… wordfence
f93e32b5-7c5d-42b9-bb4f-9a7a99793558 MEDIUM 4.4 The Mobile Navigation plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
f91ed211-9703-44fb-a2f8-8d8da910b4c7
< 0.1.16
MEDIUM 4.4 The TalkJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, a… wordfence
f8f77fa0-5bc1-41aa-aa50-6ed5436e3c63
< 1.4.2
MEDIUM 4.4 The Social Share And Social Locker – ARSocial plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad… wordfence
f8f3ce3d-ae8a-4c0f-a74d-657225a932f1
< 3.7
MEDIUM 4.4 The Buy Me a Coffee – Button and Widget Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a… wordfence
f8b8e13d-3270-4fb1-aee1-db2cf728ac55 MEDIUM 4.4 The ACF: Yandex Maps Field plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
f8a2a23c-23bf-4f23-8b9d-1d6fe869d705 MEDIUM 4.4 The Image Protector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up … wordfence
← Prev 1269 1270 1271 1272 1273 1274 1275 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top