πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1281 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
dba4317d-8624-495b-9a1f-2d4a72999129
< 2.4.3
MEDIUM 4.4 The IP Based Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
db934b29-38ed-4f95-8ad7-2d15447c5732
< 1.0.8.3
MEDIUM 4.4 The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
db7c1e07-e72b-4207-8d83-4c3e129938b7 MEDIUM 4.4 The Quick Favicon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.… wordfence
db7aaed9-2d3e-4922-ac59-80a684de6bba MEDIUM 4.4 The Panorama – WordPress Project Management Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
db510706-b916-49f5-8a09-bd254f1abbf6
< 4.5.6
MEDIUM 4.4 The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
db1f8575-aff7-43b3-83ed-8fd146914d0e
< 3.0.8.1
MEDIUM 4.4 The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress … wordfence
db18ac07-2e7a-466d-b00c-a598401f8633
< 1.3.3
MEDIUM 4.4 The Website Optimization – Plerdy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's t… wordfence
dad9b612-5575-4e64-a1b3-52a2cf3f05a7 MEDIUM 4.4 The NotifyVisitors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in versions up … wordfence
dac9e21b-b229-4e19-90cd-2748862047cf
< 1.3.6
MEDIUM 4.4 The Gum Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions u… wordfence
da919992-867f-4e17-a709-6ba7cfe350c8 MEDIUM 4.4 The Sensly Online Presence plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
da8dd02f-0d9f-44a2-bcad-1e392668dd67 MEDIUM 4.4 The Service Area Postcode Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i… wordfence
da783bb4-785a-420d-97b7-760d49678503
< 3.2.3
MEDIUM 4.4 The Simple Image Sizes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
da2dd641-6f98-4258-a758-2bfc831b3898
< 2.8.8
MEDIUM 4.4 The JS Help Desk – Best Help Desk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… wordfence
da11abe7-49fa-496b-bcd7-c666eef63896 MEDIUM 4.4 The What's New Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver… wordfence
d9e0b180-b755-4fa0-8e90-c3a61f1ca095 MEDIUM 4.4 The Dropshix plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.14 … wordfence
d9c97745-9fe2-4ae9-b083-0eda9c20ac73 MEDIUM 4.4 The Simple Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
d9a2ee71-8be5-448b-a052-1d98880ba847
< 1.3.8
MEDIUM 4.4 The WS Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
d989b1ee-13c0-4da1-80dd-38d2202f2ce7 MEDIUM 4.4 The WP Tesseract plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0… wordfence
d97ba75a-278d-4239-bfcf-53b5396fe321
< 1.0.14
MEDIUM 4.4 The Remove Footer Credit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver… wordfence
d961f6ed-778f-48ab-8d88-762be7a03617
< 1.7
MEDIUM 4.4 The pipDisqus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6 du… wordfence
d926d9fd-41b4-4d1b-9546-82f0a757a4fa
< 1.0.10
MEDIUM 4.4 The Pretty Simple Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
d9009880-d4fa-407d-9ef5-d86013190642
< 3.1.4
MEDIUM 4.4 The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is… wordfence
d8fbfcfe-3597-4c59-b47c-4e48ecbb8d83
< 3.2.8.1
MEDIUM 4.4 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin… wordfence
d8e967ce-fd36-44de-acca-c1985642ee5b
< 2.6.5
MEDIUM 4.4 The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a meta import in all versio… wordfence
d8c19868-49c2-4ee2-883a-93549e65d41a MEDIUM 4.4 The SimpleModal Contact Form (SMCF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings… wordfence
← Prev 1278 1279 1280 1281 1282 1283 1284 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top