πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1280 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
dfd67329-11b1-4f00-a422-bb4833a3181d
< 2.4.0
MEDIUM 4.4 The Chatbot for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio… wordfence
df420c75-5ebc-49ad-b721-2c6c166f7ed4 MEDIUM 4.4 The Dynamic "To Top" plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.5.2 due to in… wordfence
ded44da1-b3c5-43b6-aa9d-69d3cbf72826
< 2.2.2
MEDIUM 4.4 The WP Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.1 du… wordfence
de871598-e4e7-49f6-8530-68243544c06c
< 4.25
MEDIUM 4.4 The Maps Widget for Google Maps for WordPress is vulnerable to Stored Cross-Site Scripting via widget settings in versio… wordfence
de749c6d-c01f-4217-a1fe-020cef21f56e
< 2.8.13
MEDIUM 4.4 The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
de648bea-35c5-4611-aa2f-79e37a0299bb
< 2.0.1
MEDIUM 4.4 The WP To Do plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,… wordfence
de5e97fc-4b8d-49d0-ad8e-39931a80320c
< 1.2.75.1
MEDIUM 4.4 The MailOptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.75… wordfence
de4c147b-748e-447e-8ee7-23072445cd56 MEDIUM 4.4 The WP Database Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
de11636b-a051-4e76-bc26-ed76f66fe0df
< 1.1.2
MEDIUM 4.4 The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in versions up t… wordfence
ddee4794-5b57-4af1-a427-3247882952e9 MEDIUM 4.4 The Ricerca – advanced search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings … wordfence
ddd3487d-5c3a-4c2e-b499-0118737c08c1 MEDIUM 4.4 The Slightly troublesome permalink plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
ddc4b758-5a1e-4d0a-949e-869fcd9df0bc
< 1.7.9.1
MEDIUM 4.4 The URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to … wordfence
ddc14a98-1df8-480b-bae3-5ec057b498af MEDIUM 4.4 The Whole Enquiry Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜woow… wordfence
dda74c05-54f0-4bb5-90af-9b1256021afa MEDIUM 4.4 The Floating Social Media Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
dd9d22b0-a84a-4bf2-b8b4-89bae2970f29
< 3.1.38
MEDIUM 4.4 The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerabl… wordfence
dd773571-1f30-4b2b-8a0a-dde3ee1c53d9 MEDIUM 4.4 The Livemesh Addons for WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
dd731533-e2cd-4604-8d7a-145a0d1aadc6 MEDIUM 4.4 The Frontend Checklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
dd4db15f-e574-48f1-9e8d-bc1829035e6c
< 1.2.4
MEDIUM 4.4 The Cryptocurrency Price Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
dd300737-dda4-4ed3-b21f-0407a5e32a05 MEDIUM 4.4 The Internal Link Building plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
dc7e4235-5f40-48c2-8474-cf57af5e35bd MEDIUM 4.4 The Simple Tooltips plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up … wordfence
dc5298f9-4eb3-4ae5-afdd-59eadcd04935
< 4.7.2
MEDIUM 4.4 The WP Maps – Display Google Maps Perfectly with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
dc4c4f01-cc48-47a3-a7b7-025b261ab54c
< 6.18.4
MEDIUM 4.4 The Website Builder by SeedProd β€” Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for W… wordfence
dc19313b-f9d0-4a92-8e33-d632d8a478df
< 2.7.3
MEDIUM 4.4 The Simple Slug Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio… wordfence
dbe8d164-85c7-444d-80ad-4d03151b939b
< 1.3.2
MEDIUM 4.4 The ApexChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to… wordfence
dbd8b506-4c48-4c94-859a-a496bad83287 MEDIUM 4.4 The AWStats Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0… wordfence
← Prev 1277 1278 1279 1280 1281 1282 1283 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top