πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1273 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f891b717-738b-45fd-b355-d407785e3454
< 1.2.56
MEDIUM 4.4 The Booking Calendar Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
f888a29d-3e92-4833-85e5-081815e045c7
< 1.8.29
MEDIUM 4.4 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
f8756fb7-ee15-4fc7-b5bd-b4f2e64f8e6f
< 2.9.4
MEDIUM 4.4 The Loan Repayment Calculator and Application Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
f85df8f1-9283-48d0-8f19-88a4a839d501
< 1.7.6
MEDIUM 4.4 The TWB Woocommerce Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
f83cb847-1aa0-4fc1-a494-4f1851ce0b1c
< 3.5.0
MEDIUM 4.4 The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
f83532a8-ce5b-4df6-a464-97790cc6c04a MEDIUM 4.4 The Recipes manager – WPH plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versio… wordfence
f82ebd9f-4e8d-4465-b3b2-e71122d0aa74
< 8.8.2
MEDIUM 4.4 The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
f81950be-de32-4fa1-94fe-42667414fe2d
< 3.6.7
MEDIUM 4.4 The WP Customer Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions… wordfence
f8121633-299d-45f9-88b1-e65e30e897d1
< 3.8
MEDIUM 4.4 The Π‘Ρ‚Π°Ρ€Ρ‚ plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7 d… wordfence
f8043a78-c46a-484a-9795-c45b3bb56492
< 1.9.1
MEDIUM 4.4 The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for Word… wordfence
f7ff27af-2b78-4214-9232-042357287ba8
< 1.9.1
MEDIUM 4.4 The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Stored Cross-S… wordfence
f7e0c22a-9e36-430b-8729-990369d2ce60
< 1.2.57
MEDIUM 4.4 The Slider by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via slider settings in all version… wordfence
f7c2f45d-7ed8-4462-b769-2c4778fd6f38
< 3.8.6
MEDIUM 4.4 The Ultimate Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.8.6 due to … wordfence
f7be9241-26b6-4dd0-bd26-fdff59da3b76
< 1.5.85
MEDIUM 4.4 The KB Support plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, KB Support. This al… wordfence
f7957619-e562-4043-920d-275c58684328 MEDIUM 4.4 The Kunze Law plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's shortcode in all versions u… wordfence
f793b950-3066-45b8-bcf8-a4b4e39d4208
< 1.12.14
MEDIUM 4.4 The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin f… wordfence
f78cc71a-db22-4f5f-9231-52c66561df02 MEDIUM 4.4 The BuddyPress Global Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in versions … wordfence
f7750f70-e79c-45fb-b792-ba6a4da59964 MEDIUM 4.4 The Easy Ad Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up … wordfence
f70a19a1-d5da-4ed2-b77b-633b6841a6d4 MEDIUM 4.4 The Change From Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
f7097b64-d915-4a26-91bf-1714302c84db MEDIUM 4.4 The wp-publications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions… wordfence
f6c74bcb-b41d-4a4f-97d5-b92a3bfc794d
< 10.6.5
MEDIUM 4.4 The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers… wordfence
f68bc7e9-3bfe-4b2f-82a1-92bbde1a133a
< 7.6.13
MEDIUM 4.4 The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
f68a386b-544f-4aa2-8ae5-4d57ddd07b63
< 5.87
MEDIUM 4.4 The Hitsteps Web Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versi… wordfence
f61885bc-b7da-42b8-a0d3-ba5d7d19b536
< 1.5.1.9
MEDIUM 4.4 The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom_t… wordfence
f607b33a-58ef-4526-9ca1-aaa444aa12bc
< 2.5.1
MEDIUM 4.4 The Wp-Insert for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and inclu… wordfence
← Prev 1270 1271 1272 1273 1274 1275 1276 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top