πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1275 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f2a475f5-aafa-4717-b1a3-43f2ab8bce46
< 3.3.03
MEDIUM 4.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
f25b355a-edeb-4d88-8419-ab0d716ec5bf MEDIUM 4.4 The Flexi Quote Rotator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions… wordfence
f25626f3-d9a9-4aad-8f5f-45f72d0711e1 MEDIUM 4.4 The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
f22e9f6c-243f-4df0-bb59-57e0ad6a1f69
< 4.15.20
MEDIUM 4.4 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
f2251c72-cc98-477e-bd4d-0e134b86acce
< 1.3.0
MEDIUM 4.4 The ChatBot Conversational Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… wordfence
f213fb42-5bab-4017-80ea-ce6543031af2
< 7.1.0
MEDIUM 4.4 The Modern Events Calendar lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Google API key and… wordfence
f19006a0-6848-467b-90ed-33b3ebd2c7ba
< 3.0.20
MEDIUM 4.4 The Order date time for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings… wordfence
f16ea30d-0d03-4464-b75d-e77264af2510
< 1.0.9
MEDIUM 4.4 The Easy Custom Code (LESS/CSS/JS) – Live editing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
f15e661f-9808-4935-b2d2-42d3e7af4362 MEDIUM 4.4 The SEO Auto Linker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
f15ad88b-7dcb-4a36-877a-e7017d98d498
< 12.3.21
MEDIUM 4.4 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… wordfence
f151cb44-499e-4b08-80fb-0a573594d624 MEDIUM 4.4 The Multi-column Tag Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver… wordfence
f14478d9-2c17-48a8-a7d3-658a92a10d9c MEDIUM 4.4 The Login Logo Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
f111c87e-e1e8-45df-ab92-0a81e32467b4
< 1.19.1
MEDIUM 4.4 The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPre… wordfence
f0fa8050-6318-4528-8dd4-a3ca5467cfaa MEDIUM 4.4 The Ads Invalid Click Protection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… wordfence
f0a3a0a8-dd1d-4d10-a084-128204b411ae MEDIUM 4.4 The Debug Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
f07b166b-3436-4797-a2df-096ff7c27a09
< 3.2.0
MEDIUM 4.4 The "WebSub (FKA. PubSubHubbub)" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings i… wordfence
f04c83b9-33a0-4f4b-afc4-929d40c2ef67
< 3.2.3
MEDIUM 4.4 The JCH Optimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to,… wordfence
f037e2d8-1444-46e6-b7aa-57db812e44c5 MEDIUM 4.4 The Comments Evolved for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
f015ff9b-a7dc-47de-83d4-d6b91ec433f7
< 1.0.1
MEDIUM 4.4 The ParityPress – Parity Pricing with Discount Rules plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
efd3031f-686a-42a0-bf18-d0e8618c9a5e
< 10.6.3
MEDIUM 4.4 The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers… wordfence
efd1f2b4-6afa-4828-933b-6b390672f7c9 MEDIUM 4.4 The Server Log Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
efbf83d9-ce5e-4139-ba12-b00df4d9ad89 MEDIUM 4.4 The Nafeza Prayer Time plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
ef778a1d-d4ce-47fd-932b-9e86b38e2681 MEDIUM 4.4 The AFFILIATE Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions … wordfence
ef54b45e-19e4-4423-aace-99b017cdd6ee
< 3.1.13
MEDIUM 4.4 The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via pos… wordfence
ef462cdf-4639-405c-94c6-568645d4fa22
< 1.27.6
MEDIUM 4.4 The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
← Prev 1272 1273 1274 1275 1276 1277 1278 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top