πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1274 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f5d8616b-8757-426e-a4ae-bd851d35e296 MEDIUM 4.4 The Contact Form 7 with ChatWork plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_token' a… wordfence
f5b21bbe-32d9-4054-99ff-8f272556eda9
< 1.4.7
MEDIUM 4.4 The Snow Storm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
f5880581-3505-4851-b32f-cd2873072f73
< 2.2.4
MEDIUM 4.4 The Simple Staff List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post editor settings in vers… wordfence
f57cac64-c8c7-45c9-8079-2a727ee30872
< 2.2.9
MEDIUM 4.4 The Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
f50f1e64-5015-4e40-912e-92a4f16e1398
< 3.2.5
MEDIUM 4.4 The Top 10 – Popular posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ver… wordfence
f4dd4479-2f41-426f-b98c-7c654a82ccfe MEDIUM 4.4 The Upload File Type Settings Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ve… wordfence
f4dbab86-926d-4438-8310-19373c9bdd99
< 2.1.7.2
MEDIUM 4.4 The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜$u… wordfence
f4ba4321-23e9-4e53-ab71-e68a0bcd8129
< 2.12.1
MEDIUM 4.4 The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, … wordfence
f4943899-a25a-4e50-b33e-139ed5e8f748 MEDIUM 4.4 The Key Figures plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the kf_field_figure_default_color_… wordfence
f4544057-7384-4afe-b2bd-727d7ae25672 MEDIUM 4.4 The Gift Hunt plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.2 … wordfence
f44b8e21-4bfd-487f-96f1-d264d335f54f
< 1.1.7
MEDIUM 4.4 The GDPR Cookie Consent Notice Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
f445de97-b6fd-4180-b63e-5b8da40dae6a
< 1.0.6
MEDIUM 4.4 The WP Edit Username plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
f4421782-8a7a-4bca-8c5a-7152dfafe902
< 1.5
MEDIUM 4.4 The Debug Assistant for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and… wordfence
f41b8d18-4a20-4b99-b375-3fafb41030ee
< 1.5.1
MEDIUM 4.4 The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad… wordfence
f412bdb0-953d-4375-85c2-b87f3aa77d60
< 6.1.8
MEDIUM 4.4 The Advanced Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF post type and taxo… wordfence
f40e7f8a-8bca-4a87-887c-8e11b1da46a1 MEDIUM 4.4 The Smart Recent Posts Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al… wordfence
f3e19202-65f3-4b55-ae41-a30002a84e55
< 2.0
MEDIUM 4.4 The reCaptcha by WebDesignBy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 2.0 due… wordfence
f3cdc0ba-d28f-488c-a703-f9d880f0582e MEDIUM 4.4 The Regpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and … wordfence
f3944b2d-c431-4a53-b4e2-740480e746d6
< 1.1
MEDIUM 4.4 The Cyberus Key plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … wordfence
f334de71-9edb-491b-9bad-a2412cd2e57d
< 2.1.3
MEDIUM 4.4 The Maspik – Spam Blacklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al… wordfence
f3185d82-a785-4165-8469-abc0be38f852 MEDIUM 4.4 The WP Google Ad Manager Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
f3042586-dd23-487f-a79c-7ad5b5e38677
< 45.7.0
MEDIUM 4.4 The Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages pl… wordfence
f3022556-3c37-45d7-809a-4e991ad9e0ea
< 9.2.1
MEDIUM 4.4 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
f2f2d652-073f-4f4c-99b3-f4b99cccb45d
< 3.4.10
MEDIUM 4.4 The eBay Product Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
f2d2bce2-90a9-4b3d-875d-3fbedc397cd4
< 3.8.8
MEDIUM 4.4 The WP QuickLaTeX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Advanced' tab text field in… wordfence
← Prev 1271 1272 1273 1274 1275 1276 1277 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top