πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1279 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e30e4615-f9b6-4ff6-a227-82cace868f93
< 6.7.9
MEDIUM 4.4 The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress … wordfence
e2c837b9-c205-4fdc-8305-b9387dedd581
< 9.6.6
MEDIUM 4.4 The Salon booking system plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions … wordfence
e2b2a90f-7a0a-4150-8a24-14b2ed11663e
< 2.3.0
MEDIUM 4.4 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
e28caf56-b0b0-49dc-8489-ad5d4d8d7cfd MEDIUM 4.4 The Simple Photoswipe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio… wordfence
e279f923-e30d-45b6-9734-2bd50731c33c
< 2.5.1
MEDIUM 4.4 The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
e262ec15-420a-4f52-90e0-e4a2e28402a1 MEDIUM 4.4 The Mandatory Field plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions… wordfence
e23abd25-d41b-4ba8-a5b7-993f745d375a
< 3.0.0
MEDIUM 4.4 The Double the Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
e1ff2c57-c3b7-4747-9f99-665774dc2054
< 1.9.1.6
MEDIUM 4.4 The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress i… wordfence
e1e82300-9b18-4938-84ac-7d4ee8c21875
< 4.2
MEDIUM 4.4 The Export All URLs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
e1cc3dbe-26e3-478f-9574-f57ffa0f50c3
< 4.12.2
MEDIUM 4.4 The Ajax Search Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
e1a20ca8-8eb8-4247-9145-63bcb0d5d681
< 1.8.3
MEDIUM 4.4 The Search Atlas SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
e18aceee-edbb-45ae-8f5e-6bce2aed65b6 MEDIUM 4.4 The GoUrl Bitcoin Payment Gateway & Paid Downloads & Membership plugin for WordPress is vulnerable to Stored Cro… wordfence
e116f1f1-ef11-408f-8368-ddd94ba50b41 MEDIUM 4.4 The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
e0f356ce-1937-4c89-bedc-f25ea4e78264
< 2.5
MEDIUM 4.4 The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versi… wordfence
e0df4422-0ca1-42cb-acc1-27a92d6af12b
< 2.4.0
MEDIUM 4.4 The Posts Footer Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
e0dd2417-54b5-4838-88da-1893559bd255 MEDIUM 4.4 The Nokaut Offers Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio… wordfence
e0d525ab-a86d-4750-9d16-731cbc0a626e
< 2.0
MEDIUM 4.4 The Weaver Show Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_class' parameter in… wordfence
e0a0303a-2c8e-4ac5-ad89-df3774db9679
< 2.5.3
MEDIUM 4.4 The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
e09c629b-9908-4548-b828-9e6140ff5670
< 1.6
MEDIUM 4.4 The Cab Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and… wordfence
e0403a76-86ce-4772-bc0b-22b183f0f684
< 5.5.2
MEDIUM 4.4 The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via in versions… wordfence
e02472a8-5b88-43ad-86f3-e890b49899ad
< 2.5
MEDIUM 4.4 The Add Widget After Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… wordfence
e02372a0-5d10-4d1a-9499-6f6b53fb477e
< 1.9.71
MEDIUM 4.4 The Postie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, a… wordfence
e01fd891-631e-47df-9f29-f3d4d5afa02f
< 2.8.9
MEDIUM 4.4 The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
e016213f-b06f-4a9d-a2c6-3b4dd1b6b571 MEDIUM 4.4 The Bootstrap Multi-language Responsive Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
dfea441c-2e77-47fa-8f6e-8d17d0c90ebe
< 4.4.7
MEDIUM 4.4 The Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor is vulnerable to Stored Cr… wordfence
← Prev 1276 1277 1278 1279 1280 1281 1282 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top