πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1284 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d170af2a-9b8c-43ad-b712-b89bcfadd5b7
< 1.2.16
MEDIUM 4.4 The Ultimate Maps by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… wordfence
d16a3da0-9539-4555-8dfc-65cb4f4d7b4d
< 3.1.7
MEDIUM 4.4 The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the critical css rules in versions… wordfence
d1647a2c-d21d-4b4b-a22e-32351022404e
< 1.2.1
MEDIUM 4.4 The Logo Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up t… wordfence
d131115b-e2c9-42c6-9262-a19272944652
< 1.5.1
MEDIUM 4.4 The Panorama – WordPress Project Management Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
d0e6900c-21a3-4b46-bb61-8c41e2234a26 MEDIUM 4.4 The Continually plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
d09ea234-f04e-4337-851e-b42bbf6f8901 MEDIUM 4.4 The WP Biographia plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… wordfence
d082c6e6-a18a-44e2-9478-7189f9777198
< 4.9.5
MEDIUM 4.4 The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulne… wordfence
d050b5a4-efd1-45d5-a3f7-13fa9e19ab37
< 2.3.15
MEDIUM 4.4 The Responsive Gallery Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
d00c6fe3-5914-46e1-9a00-0641d17aa79f
< 4.15.20
MEDIUM 4.4 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
CVE-2026-6812 MEDIUM 4.4 The Ona theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.26 via … nvd
CVE-2026-2716 MEDIUM 4.4 The Client Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Testimonial Hea… nvd
CVE-2026-2499 MEDIUM 4.4 The Custom Logo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … nvd
CVE-2026-2498 MEDIUM 4.4 The WP Social Meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … nvd
CVE-2026-2489 MEDIUM 4.4 The TP2WP Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Watched domains' textarea … nvd
CVE-2026-2292 MEDIUM 4.4 The Morkva UA Shipping plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… nvd
CVE-2026-2289 MEDIUM 4.4 The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … nvd
CVE-2026-2282 MEDIUM 4.4 The Slidorion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to… nvd
CVE-2026-2281 MEDIUM 4.4 The Private Comment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Label text' setting in al… nvd
CVE-2026-1649 MEDIUM 4.4 The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ce_venue_name' parameter… nvd
CVE-2026-1055 MEDIUM 4.4 The TalkJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, a… nvd
CVE-2026-1047 MEDIUM 4.4 The salavat counter Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_url' paramet… nvd
CVE-2026-1044 MEDIUM 4.4 The Tennis Court Bookings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… nvd
CVE-2026-1043 MEDIUM 4.4 The PostmarkApp Email Integrator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settin… nvd
CVE-2025-12451 MEDIUM 4.4 The Easy SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versi… nvd
CVE-2025-12037
< 1.0.6
MEDIUM 4.4 The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set… nvd
← Prev 1281 1282 1283 1284 1285 1286 1287 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top