πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1278 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e6292935-a67e-4b59-9b3c-0b71365193b7
< 1.0.3
MEDIUM 4.4 The Custom Base Terms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'base' parameter in vers… wordfence
e61b6e54-b330-41a5-b13f-ba11c10d8bfe
< 6.1.10
MEDIUM 4.4 The Simple File List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in versions up to, a… wordfence
e6090a49-f3dc-4b7b-bc86-eb7ec57b7ba4
< 2.6.0
MEDIUM 4.4 The Stock Locations for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings… wordfence
e5eea72d-f10b-460b-be00-bb5b1c4a1a62
< 1.0.27
MEDIUM 4.4 The Image Optimizer WD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions… wordfence
e5a44629-af3f-4bc7-8e68-bbe7df3747f1
< 1.8.5.3
MEDIUM 4.4 The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) plugin … wordfence
e56b11a1-dd40-461b-9624-b60367c0c727 MEDIUM 4.4 The Product Visibility by Country for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
e5696067-a98b-49ad-b078-571c889f1272
< 2.7.7
MEDIUM 4.4 The MB Custom Post Types & Custom Taxonomies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin… wordfence
e565c855-2e2f-4577-8cf2-e167f5fe5f37
< 2.0.0
MEDIUM 4.4 The HD Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and in… wordfence
e55f6d1d-b0b3-41e6-9ca9-c6e9f6dd34ed MEDIUM 4.4 The CC & BCC for Woocommerce Order Emails plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
e5482dd5-edb0-4208-a864-e9a3dd89d557
< 1.5.1
MEDIUM 4.4 The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
e53878e4-659a-4530-8bb7-a9c7a2e3bc1e
< 2.4.1
MEDIUM 4.4 The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
e5343bc9-5dcd-410b-a7b7-27734910ad3c
< 2.11.21
MEDIUM 4.4 The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up… wordfence
e5103e60-771f-46cf-b432-21d131e30bcc
< 3.7.6
MEDIUM 4.4 The Ultimate Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions … wordfence
e4b3b3be-0c3a-43d0-b7d3-3f61b09175f2 MEDIUM 4.4 The My Default Post Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
e46139c8-dd7e-4904-81b2-283952cea9b5 MEDIUM 4.4 The Easy Coming Soon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versio… wordfence
e44403cd-1cee-43c4-aabc-3eaad433c020 MEDIUM 4.4 The WP Content Permission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ohmem-message' para… wordfence
e43fb223-8b0a-4232-8e15-43f8b38652c1
< 1.15.1
MEDIUM 4.4 The WP Smart Preloader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions … wordfence
e40f07b5-9e6e-430b-86fc-3bb863a51b01
< 14.46
MEDIUM 4.4 The WP GoToWebinar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in versions up to, and… wordfence
e40ce073-f865-47d8-bdda-3609beea65b0
< 1.6.60
MEDIUM 4.4 The Bricksable for Bricks Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
e3d8daef-787d-43f1-a438-958295294f6c MEDIUM 4.4 The Movie Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … wordfence
e3c52d28-54de-403c-b874-680e10e3fc3c MEDIUM 4.4 The Advanced Page Visit Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
e3b81a8f-e10f-4eaf-9c45-21208bc9411d
< 4.15.9
MEDIUM 4.4 The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress i… wordfence
e3ab817c-3677-4251-adaf-f340bf4c5336
< 4.0.0
MEDIUM 4.4 The DBargain plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings parameter in versions… wordfence
e324cd49-beaf-44bf-8890-5377731f0cc5
< 2.2.4
MEDIUM 4.4 The Social Proof (Testimonial) Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settin… wordfence
e31d8218-5e04-44a1-89aa-f93e9677680b
< 8.2.3
MEDIUM 4.4 The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to Sto… wordfence
← Prev 1275 1276 1277 1278 1279 1280 1281 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top