ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1295 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ad77a2a3-e24b-43f0-b066-1774ab20e2cd
< 1.0.334
MEDIUM 4.4 The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.0.334 due… wordfence
ad374338-2bf4-4322-be5e-b4fe07acf80d
< 1.6.9
MEDIUM 4.4 The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
ad1a79f3-274f-4a33-a752-669c09c2d47d MEDIUM 4.4 The Redirect After Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in ve… wordfence
ad07299f-8cff-4bc7-9953-2cea08f3d29c MEDIUM 4.4 The Read More Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
acf1ce69-0bf9-4329-973f-3796c8bb8895
< 5.1.3.6
MEDIUM 4.4 The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1… wordfence
ac8a06f5-4560-401c-b762-5422b624ba84
< 2.8.13
MEDIUM 4.4 The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (… wordfence
ac897ade-1bf0-41f2-b304-456817e66ce5
< 2.5.0
MEDIUM 4.4 The Woostify theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.2 du… wordfence
ac6e587c-59b2-4f93-ab88-5e548b52db45
< 3.9.10
MEDIUM 4.4 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
ac6201a1-7ca9-461b-b9ad-16407120dfae
< 4.7.2
MEDIUM 4.4 The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automatic r… wordfence
ac23c688-b3d7-4844-ac94-0cbd798bce4c
< 20250114
MEDIUM 4.4 The Simple Basic Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al… wordfence
ac1fb279-df40-467e-a336-fa67468c2b78
< 2.2.4
MEDIUM 4.4 The StreamCast – Radio Player for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sett… wordfence
ac1239c9-72a6-44d8-911f-70a528c66c62 MEDIUM 4.4 The EZP Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in ve… wordfence
ac08bd5c-3bcf-44e8-8555-d30fdf073dba MEDIUM 4.4 The Terms of Service & Privacy Policy Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ver… wordfence
abb4b617-884b-4e72-812f-5f23a0976ab6
< 4.2.6.4
MEDIUM 4.4 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Course… wordfence
aba36c3b-beae-4c47-8aa8-5012a7a838ce
< 2.6.7
MEDIUM 4.4 The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is … wordfence
ab86ddc9-9b43-4949-b150-7b944bc40558
< 3.2.8
MEDIUM 4.4 The SparkPost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up t… wordfence
ab81622e-430f-415d-b3ab-41edd5436131 MEDIUM 4.4 The Viet Affiliate Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers… wordfence
ab004836-8362-46d6-acfc-80f582605b43
< 5.5.16
MEDIUM 4.4 The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu… wordfence
aae94aa1-a7a9-43df-b958-4fcf0392335b
< 1.11.8
MEDIUM 4.4 The Z-Downloads plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.11… wordfence
aa7aad43-54b4-4b9f-9584-292e40be71bc MEDIUM 4.4 TheWP资æºä¸‹è½½ç®¡ç† plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version… wordfence
aa464547-0380-4b91-a5ea-0cd9a66da7a7
< 4.9.17
MEDIUM 4.4 The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
aa4377a8-bcf4-45ba-824b-3505bd8e8c61
< 3.6.3
MEDIUM 4.4 The Content Views – Post Grid, Slider, Accordion (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable t… wordfence
aa19eb88-b47a-4438-accf-d98241b927af
< 1.15.30
MEDIUM 4.4 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Store… wordfence
aa13426a-2d4e-4268-bc0d-e496bc9e6f33
< 1.3.3
MEDIUM 4.4 The Ko-fi Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to,… wordfence
a9cf7103-e644-4328-bd14-e8fd53f9489b
< 1.0.14
MEDIUM 4.4 The Premmerce User Roles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
← Prev 1292 1293 1294 1295 1296 1297 1298 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top