πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1277 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ea59d04e-b332-49f8-bf3f-6e0cda3be712
< 4.0.4
MEDIUM 4.4 The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
e9a65dc9-4c9a-4f19-bd1f-2ca8a6ded18c MEDIUM 4.4 The AI Contact Us Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions … wordfence
e91a92c2-d8df-49e1-8c08-0df7fa7c6829
< 3.95.0
MEDIUM 4.4 The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Sto… wordfence
e8e2519e-89cc-455f-921c-fe6b10f1dc26
< 3.2.4
MEDIUM 4.4 The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3… wordfence
e8d41006-ab36-4eed-8c17-2937ca7aff1b
< 2.1.9
MEDIUM 4.4 The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio… wordfence
e8b7e4cd-6290-4d58-b43b-52d010028007
< 2.1.15
MEDIUM 4.4 The Breeze plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.14 du… wordfence
e8b5bc1b-c9dc-4ce5-86db-2802f5b49d0b
< 1.7.0
MEDIUM 4.4 The Nooz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and inc… wordfence
e87209a2-a18e-40e3-b0ba-9ee548a36e8e
< 1.0.77
MEDIUM 4.4 The Polls CP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,… wordfence
e85ee611-ae81-4736-b4f0-b9d06714da18
< 6.4.6.0
MEDIUM 4.4 The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable t… wordfence
e82e7745-4642-43c3-9bce-12384b9d9309
< 4.2.3
MEDIUM 4.4 The Multipurpose Ticket Booking Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
e818a5db-acb7-4b16-80b1-939904e93791 MEDIUM 4.4 The Email posts to subscribers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in v… wordfence
e80bb7de-ce18-40d5-bf4c-9616739b2f9d MEDIUM 4.4 The Webmaster Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions… wordfence
e7e25e64-4504-4aad-aeb6-d58b5c36a4bd
< 1.29.3
MEDIUM 4.4 The Time Sheets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … wordfence
e797c0ca-f348-4d9c-815e-0c1756686690 MEDIUM 4.4 The Electric Studio Client Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… wordfence
e78dd70a-c2e3-4192-957f-6f30fed20667 MEDIUM 4.4 The Aria Font plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4 du… wordfence
e781e1aa-7fa2-4cea-913b-4aa582ec6a4f
< 2.0.20
MEDIUM 4.4 The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via headers/footers in all versions up to, … wordfence
e76ba53c-1b17-4bc0-b8b8-6a851f47be68 MEDIUM 4.4 The Melipayamak plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.… wordfence
e74be387-1413-49c5-91c6-66e620562b42
< 7.6.6
MEDIUM 4.4 The Hustle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and i… wordfence
e7465ca4-21e8-4935-b294-e7378b2b01a7
< 6.10.5
MEDIUM 4.4 The Modern Events Calendar lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Google API key and… wordfence
e7028184-2b16-45a8-893a-37eb74bab329
< 2.3.5
MEDIUM 4.4 The WRC Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
e6dbbb52-4202-4d69-837f-c7d5ca06fab5
< 3.7.2
MEDIUM 4.4 The Popup Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, an… wordfence
e6c01d91-a912-4826-97eb-fd77368ae117
< 3.59.1
MEDIUM 4.4 The NextGEN Gallery – Create an Amazing Photo Gallery in Seconds plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
e688febc-b51b-496a-9ff7-452300956838
< 5.3.2
MEDIUM 4.4 The MailPoet – Newsletters, Email Marketing, and Automation plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
e651766b-705d-415d-90bc-8b4f4418222c
< 1.2
MEDIUM 4.4 The Custom Field For WP Job Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
e642b5e1-62c1-4aa9-b579-6b2338227dd5
< 1.2.8
MEDIUM 4.4 The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored Cro… wordfence
← Prev 1274 1275 1276 1277 1278 1279 1280 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top