πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1285 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cff3bfae-bda7-4ab1-b6f5-11bd0dfd75b8
< 4.7.7
MEDIUM 4.4 The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.6 d… wordfence
cfea29b2-03dd-4d48-9cbf-c80017cd2b17
< 1.9.0
MEDIUM 4.4 The Notely plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.0 due… wordfence
cfe2cabd-98f6-4ebc-8a02-e6951202aa88
< 9.7.6
MEDIUM 4.4 The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti… wordfence
cfdd7e9f-a2a5-43ac-8eb1-b9723e932db9 MEDIUM 4.4 The Click & Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.… wordfence
cfd8a6a4-9159-480f-abe2-71972585217b
< 2.1.0
MEDIUM 4.4 The Quick Restaurant Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters … wordfence
cfc6c5cd-208c-433f-9121-9d0c101b587d
< 5.28.4
MEDIUM 4.4 The Event Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.… wordfence
cfb48c2e-9447-4fd1-a5a4-d9b675276ced MEDIUM 4.4 The Frontend Checklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Items in all versions up to… wordfence
cfb27513-61ad-4cf0-a471-0ab7aeb0801b
< 10.6.7
MEDIUM 4.4 The RSVPMarker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, a… wordfence
cf643f14-bbca-40ee-bce0-648e50d17ca9
< 4.3.4
MEDIUM 4.4 The CM Tooltip Glossary plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers… wordfence
cf4a3171-f041-40ce-8148-239c24d7ce95 MEDIUM 4.4 The Telegram for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions… wordfence
ceb950f4-0ca6-45d1-b261-c8fa045bc555 MEDIUM 4.4 The Inboxify Sign Up Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
cea30a5d-2074-48b1-aca5-7c502e496961
< 1.2.9.2
MEDIUM 4.4 The Email Template Customizer for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admi… wordfence
ce9aa906-72be-4551-9850-76f0adb6da97
< 1.9.3
MEDIUM 4.4 The SlickNav Mobile Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver… wordfence
ce75f50d-a9d9-4e4e-85b2-6e15ffa77a94
< 6.9.4.4
MEDIUM 4.4 The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
ce106c3a-e99b-4182-84d8-8f896edbbefd
< 1.2.35
MEDIUM 4.4 The WP Custom Fields Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in vers… wordfence
ce01e7c9-1ffc-4cc4-a1e4-dc67861db410 MEDIUM 4.4 The Text Selection Color plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
cdffbef4-5462-49b2-a97e-6a497147bc41 MEDIUM 4.4 The Comment SPAM Wiper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' setting in al… wordfence
cde92185-d63a-47b3-a17e-3f2b2b20270c MEDIUM 4.4 The WP-dTree plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to… wordfence
cdd563b7-a1b9-4d99-9a6e-c8acf9dda619
< 3.2.19
MEDIUM 4.4 The Membership Plugin – Restrict Content for WordPress is vulnerable to Stored Cross-Site Scripting via multiple invoi… wordfence
cdcac5f9-a744-4853-8a80-ed38fec81dbb
< 0.9.90
MEDIUM 4.4 The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s… wordfence
cdc5ef6a-32d8-4c4b-b459-d9b543b56898
< 5.5.14
MEDIUM 4.4 The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin… wordfence
cdb3fbaa-4d33-4754-848b-77e902ea4a85
< 4.5.1
MEDIUM 4.4 The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, a… wordfence
cd831fdb-9b06-4e4e-9423-d221fd3aa69a MEDIUM 4.4 The Cookie Warning plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
cd4d6cbf-cec5-4fd2-af8e-698cf25da40b
< 1.5.1
MEDIUM 4.4 The Werk aan de Muur plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
cd312b95-03b1-4d0f-8bb4-712900557c67 MEDIUM 4.4 The Tabs – Responsive Tabs with WooCommerce Product Tab Extension plugin for WordPress is vulnerable to Stored Cross-S… wordfence
← Prev 1282 1283 1284 1285 1286 1287 1288 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top