πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1286 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cd156e40-7706-493b-918b-c9be45040cb5 MEDIUM 4.4 The eZee Online Hotel Booking Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
ccf00ec5-b91a-47db-81e6-68f984b8f06b
< 8.8
MEDIUM 4.4 The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
ccea6d3e-a889-4058-a9ff-e75b8de16ba0
< 4.2.9
MEDIUM 4.4 The Survey Maker – Customer Satisfaction Survey, Chat Survey, Calculaton Form, Payment Surveys plugin for WordPress is… wordfence
ccb518a4-bdc7-463e-95b7-0628c566aab8
< 1.8.0.4
MEDIUM 4.4 The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via "Geoloca… wordfence
cc7689ea-3e7b-4367-872d-fa036a29f842
< 3.6.4
MEDIUM 4.4 The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
cc74e973-90ab-4678-a035-82b4b2b85604
< 3.9.0
MEDIUM 4.4 The I Recommend This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up… wordfence
cc554199-8c5c-4cce-a103-46a4a8450bf3 MEDIUM 4.4 The Blog Manager WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
cc4af854-13a5-416f-ac97-aba7a6e85732 MEDIUM 4.4 The Custom Comment plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
cbf193ef-e172-4fe3-9bff-b5cbac9adb54 MEDIUM 4.4 The illi Link Party! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
cba77ced-412e-4461-8d2a-980371c78a17
< 3.4.2
MEDIUM 4.4 The Dashboard Widgets Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
cb93a5f2-9bcf-4b06-aad7-ba36c7dea714
< 1.4.9
MEDIUM 4.4 The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable… wordfence
cb4eb28a-3dd5-4d8d-bef0-53cee7285180 MEDIUM 4.4 The Simple Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … wordfence
cb2f764f-1e50-4e42-9b70-88f9967906fd MEDIUM 4.4 The WP File Download Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all version… wordfence
cb269a48-e813-4cda-821a-ee70431372d2
< 6.0.2.1
MEDIUM 4.4 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … wordfence
cb0fee1c-9dac-497c-a364-3b616e4b8ac0
< 9.6.2
MEDIUM 4.4 The PixelYourSite – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… wordfence
cae15a1c-63bc-4349-aba3-7f34737d6045
< 3.8.1
MEDIUM 4.4 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
ca954d68-18a5-47e2-af56-261c7a55b017
< 1.1.3
MEDIUM 4.4 The CRM Perks Forms – WordPress Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm… wordfence
ca91046d-61c1-4a65-a078-c7dffb27092c
< 7.6.0
MEDIUM 4.4 The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to Store… wordfence
ca8fe2c6-2a7e-4fed-baf0-c8a4979ab966 MEDIUM 4.4 The WordPress Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
ca7f1b56-a732-40c1-a05e-4ab3e6b05037
< 1.8.1
MEDIUM 4.4 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
ca5bc2af-394b-4fc1-b6c3-ed9ff0a5959a
< 2.0.24
MEDIUM 4.4 The Beds24 Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
ca449d15-b05e-4341-99b0-472a14cab8f4 MEDIUM 4.4 The GPS Plotter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … wordfence
ca33e88f-e76d-45ef-a8da-153f02214913
< 3.5
MEDIUM 4.4 The Admin Dashboard RSS Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
ca329b94-1d4c-439c-b45a-6b39ccf3d1eb
< 5.2.1
MEDIUM 4.4 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vul… wordfence
ca29baf1-7214-4569-9106-6d369e9f4d6f
< 2.12.2
MEDIUM 4.4 The Simple Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
← Prev 1283 1284 1285 1286 1287 1288 1289 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top