πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1282 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d8b5b320-9283-4072-be65-f5c62ca29b35
< 1.3
MEDIUM 4.4 The Time Clock plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.3… wordfence
d88eb628-09c9-451c-b5ae-f26a93514447 MEDIUM 4.4 The Continuous announcement scroller plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin se… wordfence
d862e8e6-ecf6-41f5-8f40-1225ecec7e1f MEDIUM 4.4 The New Adman plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, an… wordfence
d851760a-e72c-4cd1-9399-9a54c126a30a
< 1.9
MEDIUM 4.4 The Recurring PayPal Donations plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
d7b67c83-7fb7-4bac-a8eb-7fc318f2ff50
< 1.4.1
MEDIUM 4.4 The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulner… wordfence
d769dd4f-f885-47e3-b39f-2ef3ae4a4f63 MEDIUM 4.4 The Easy Elements Hider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
d7526228-4e21-430c-90ad-1476c81698ad MEDIUM 4.4 The Wikilookup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Popup Width' setting in all ve… wordfence
d74f5813-cf7a-4ffb-9306-56f29b3a7d04 MEDIUM 4.4 The Order Delivery Date for WP e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se… wordfence
d732ea2d-c763-4735-b541-6c5fd5167cb4 MEDIUM 4.4 The WeSecur Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up… wordfence
d713ff91-30ba-474d-87ca-39b15c77b30a
< 1.15.25
MEDIUM 4.4 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Store… wordfence
d7051345-8ca6-42e0-95fb-e127e65a5ef2
< 2.6.9
MEDIUM 4.4 The Carousel, Slider, Gallery by WP Carousel – Image Carousel with Lightbox & Photo Gallery, Video Slider, Post Carous… wordfence
d7023a3e-35ba-4d52-8092-ae40b53d5efa
< 7.8.5
MEDIUM 4.4 The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
d6a866b4-e915-4b60-ac76-e65f698e73c4 MEDIUM 4.4 The CookieCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.4… wordfence
d6a60159-5aa6-40fd-a1ea-320b56fd8b91 MEDIUM 4.4 The Simple Popup Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver… wordfence
d6558119-35fe-4aa9-8e5a-4b9df329d8b6 MEDIUM 4.4 The Dashboard Beacon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
d632bc58-f441-48fb-848c-40b22d3aa562 MEDIUM 4.4 The Review Map by RevuKangaroo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings… wordfence
d6203da8-8cf0-4bd8-8ecb-3e2ec787bf6f
< 3.10.1
MEDIUM 4.4 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
d61ed3e3-5102-4293-a999-e324e721ab89 MEDIUM 4.4 The Sponsors Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the an image title in versio… wordfence
d5f82abe-64bb-4539-8fe7-261fad60cfa9
< 3.5.10
MEDIUM 4.4 The Modal Dialog plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5… wordfence
d586e455-c73f-4916-a926-4d53699bb434
< 5.30.10
MEDIUM 4.4 The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm… wordfence
d574ed8b-2887-4a56-9fca-914148095ba1 MEDIUM 4.4 The AN_GradeBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to,… wordfence
d55b210f-bbed-4206-a109-99f217a2eb67
< 4.0.24
MEDIUM 4.4 The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress … wordfence
d549fcd5-6808-4d7d-bf1f-df8cfa458744
< 3.6.0
MEDIUM 4.4 The Bulk Order Form for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings… wordfence
d5211437-9c6d-435f-a7f2-17ed754d0fab MEDIUM 4.4 The Task Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin… wordfence
d4fb697f-4571-4aa8-8430-fd4f457de2a8
< 1.8.0.4
MEDIUM 4.4 The Simple Website Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
← Prev 1279 1280 1281 1282 1283 1284 1285 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top