πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1276 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ef1aafc2-e47b-49da-8a4e-9111209308c2 MEDIUM 4.4 The LeadSquared Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in versions up to, … wordfence
ef0324f2-f897-42a9-a7dc-0483728a05c8 MEDIUM 4.4 The AvaiBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2 due… wordfence
ee88099f-6f35-461c-b485-f7ffd77ec6c4 MEDIUM 4.4 The WP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
ee7513d9-e76c-4da4-919b-ba376f0c4022 MEDIUM 4.4 The BizLibrary plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, a… wordfence
ee0a9e78-c9a3-40c8-8e4b-4a67c3124fb3 MEDIUM 4.4 The Request Call Back plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
ee013d3f-18bc-418e-ab5b-87724710f340 MEDIUM 4.4 The Onclick Show Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions … wordfence
edf2e060-5ae4-4b46-bc68-22ae5f516fe8
< 6.4.6.0
MEDIUM 4.4 The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable t… wordfence
edd13a5a-6c2d-4c19-941f-9b367cc32dde MEDIUM 4.4 The Float Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
edafc213-a95f-483e-ac5f-d5b56817d046
< 2.7.11.11
MEDIUM 4.4 The Groundhogg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via task data in versions up to, and in… wordfence
eda538ef-c053-4347-b345-d5d03db25a01
< 6.1.81
MEDIUM 4.4 The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
ed8cd92a-c791-4781-a7bc-9b2a4d559d7d
< 2.1.7
MEDIUM 4.4 The Back To The Top Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versi… wordfence
ed88270e-d6e1-431b-bca6-b594ec6bc609
< 6.4.2
MEDIUM 4.4 The Widget for Social Page Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… wordfence
ed402a8d-0273-4172-8695-afc9b47f51a4
< 5.2.62
MEDIUM 4.4 The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
ed37e94b-406c-4203-a1a8-c61cc6073ee1 MEDIUM 4.4 The Elegant Visitor Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
ed0a37cc-49db-4919-8d0d-cb7739332229
< 1.3.21
MEDIUM 4.4 The Product page shipping calculator for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
ecbe6b38-6865-4bc7-a0ba-4e4a91a5d6ba MEDIUM 4.4 The Form Generator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
ec9029a3-be05-469a-a8e2-20987a4a4ad9
< 3.2.7
MEDIUM 4.4 The Nested Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
ec860ad9-7054-4ed2-a8f2-6589e4db36cd MEDIUM 4.4 The wp tell a friend popup form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings ver… wordfence
ec2daf19-51ef-4e1b-becb-252955a61523
< 2.2.8
MEDIUM 4.4 The EventON plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, … wordfence
ebfc2677-6e5c-49f2-915b-b07af8c2037d
< 6.6
MEDIUM 4.4 The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, … wordfence
ebafc14a-1197-4ac4-ad95-8965a755d5c4
< 2.5.18
MEDIUM 4.4 The Search & Filter Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers… wordfence
eb94520e-a99d-4e34-b174-e01898de0978
< 5.0.0
MEDIUM 4.4 The Custom post types, Custom Fields & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin … wordfence
eb6036a5-4667-481f-93fb-e8ee7cd42c83 MEDIUM 4.4 The Plugin Security Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
eb43502e-dedd-46ff-b8e8-68298779f125 MEDIUM 4.4 The Trail Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
eb1f5fc6-9e0e-423a-bd71-32e12d201c37 MEDIUM 4.4 The Search Keyword Redirect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
← Prev 1273 1274 1275 1276 1277 1278 1279 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top