πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1289 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c31cd87c-8e28-49f2-8e38-151acb1c99ce MEDIUM 4.4 The Like dislike plus counter | Like Dislike Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
c312f915-fca6-4624-bfb9-8d8fd54d1b3c
< 1.7.29
MEDIUM 4.4 The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
c2f4c1de-7eeb-45c4-bbff-ec85f2cda5aa
< 3.8.7
MEDIUM 4.4 The Event Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mep_get_opt… wordfence
c2e83cb5-3c10-45dc-b37e-4d47ebc6853d
< 1.5.1.3
MEDIUM 4.4 The Landing Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version… wordfence
c2ad4325-be1f-48c1-b21f-adf9ce3fa2cb
< 3.9.8
MEDIUM 4.4 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulne… wordfence
c2a5ae9f-b57c-4a71-b976-5975ad086c74
< 1.0.3
MEDIUM 4.4 The Wp-Adv-Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a quiz question and message in all… wordfence
c29b9cb5-fd47-47d6-a341-a4b5ca0683f1
< 4.7.2
MEDIUM 4.4 The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to St… wordfence
c2330359-447e-4871-b364-620d9b065f70 MEDIUM 4.4 The Contact Form 7 Star Rating with font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via s… wordfence
c226ca9a-8a2e-4e56-a039-96c31526a379 MEDIUM 4.4 The WolfNet IDX for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al… wordfence
c2036c08-3aaf-4e41-bcd6-787f4b8fba9d
< 1.1.151
MEDIUM 4.4 The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versi… wordfence
c20059de-9d81-4318-a015-8e402945828c
< 1.0.6
MEDIUM 4.4 The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set… wordfence
c1ee67ea-5500-4c06-bfda-5d5bf32db4ef MEDIUM 4.4 The Search by Google plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
c1b1bdaf-eeec-4f93-86d6-cb94db6c32f8 MEDIUM 4.4 The Global Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
c1ac9f77-eea7-4726-b2ba-019c26aec242
< 2.7.6
MEDIUM 4.4 The NPS computy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
c198008f-271e-431e-beb9-3a9f93cbbf8e
< 2.1.0
MEDIUM 4.4 The Wp Ultimate Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions … wordfence
c17967a4-20df-4b23-973f-591a0caeea39
< 1.2.7
MEDIUM 4.4 The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, an… wordfence
c16c3a8d-bae1-4729-86c8-ec13481ff187
< 1.2.12
MEDIUM 4.4 The Filr – Secure document library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unrestricted … wordfence
c16918a9-7b73-418d-adbd-aa17cb1d8cf8 MEDIUM 4.4 The Cookie consent for developers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple setting… wordfence
c1022ac4-869e-415a-a7c8-3650421608ea
< 4.0.17
MEDIUM 4.4 The ARMember Lite - Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in v… wordfence
c0a5e6b9-4da1-4d95-9fb1-aabb0d21b695 MEDIUM 4.4 The Nari Accountant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via account settings in all versio… wordfence
c08ffe26-23a0-40d8-91ad-19be59cf38a3 MEDIUM 4.4 The Risk Free Cash On Delivery (COD) - WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
c0693caa-2c7e-4e9f-8829-1883876d6966
< 1.31
MEDIUM 4.4 The Flipping Cards plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
bfe8d13b-f387-4c82-ba9f-efadda18c882
< 3.11.1
MEDIUM 4.4 The Easy Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
bfd158b2-c6a4-441a-b611-bf06e197d13d
< 2.1.2
MEDIUM 4.4 The PopupAlly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to… wordfence
bfa62b92-e712-416c-a7f9-634cf3db307e MEDIUM 4.4 The Spoki plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.16.0 due… wordfence
← Prev 1286 1287 1288 1289 1290 1291 1292 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top