πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1296 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a9bbcb41-d604-45ec-a36a-4b41e8f7a508
< 7.0.2
MEDIUM 4.4 The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a… wordfence
a9b2b094-9a2d-4c73-be5f-b2a6f3da9233 MEDIUM 4.4 The Don8 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in versions up to, and in… wordfence
a94dfee0-217f-4c83-8ec5-660fb174a5c5 MEDIUM 4.4 The Page Transition plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
a920d8c0-fb6b-40dc-ae61-ac004b0dfccd
< 1.3.5
MEDIUM 4.4 The Quick Playground plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.4. T… wordfence
a90ea845-9f7f-4a89-887d-cf4337f8471f
< 2.3.5
MEDIUM 4.4 The Google Analytics Opt-Out for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions u… wordfence
a89f795d-246d-4a3c-a7a7-5c9867d7a01e
< 1.4.7
MEDIUM 4.4 The Custom Post Carousels with Owl plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
a885e5db-dc84-46db-960e-63f62709e1b1 MEDIUM 4.4 The Crelly Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
a86d8f97-54dc-4c6b-92c0-05a8625cc073
< 3.5.4
MEDIUM 4.4 The Scripts n Styles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up… wordfence
a8604854-380a-4fd9-aaed-85387c0e3046 MEDIUM 4.4 The issuuPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2… wordfence
a80a3108-c685-4e26-9ecd-a0fe6ad4860c
< 4.10.34
MEDIUM 4.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via several… wordfence
a7ed1cbd-1dd0-4996-8255-91a9131934c0
< 1.3.2.9
MEDIUM 4.4 The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3… wordfence
a7dd1215-af79-45db-9893-a5f4299e1343
< 7.6.47
MEDIUM 4.4 The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
a798ffe0-b81d-4c5f-a864-ed72a5312a16
< 1.2.6
MEDIUM 4.4 The Advanced Floating Content Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
a7826d47-8799-446f-af3c-df2724fb26ef
< 1.1.127
MEDIUM 4.4 The Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, a… wordfence
a745ce1b-13fd-470d-9685-62dfc11c9bd5 MEDIUM 4.4 The Link View plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.8.0 … wordfence
a714b35e-776d-42f4-bb7c-7865bf2b7637
< 3.8.1
MEDIUM 4.4 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
a7147719-17cf-4381-b371-6d9162ef3e35
< 1.4.9
MEDIUM 4.4 The AWEOS WP Lock plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
a71191f3-1151-4f8c-b6fe-86983b034557
< 6.5.9.9
MEDIUM 4.4 The Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
a6d43f93-0315-4060-a8a6-7e9cdd8447af
< 3.13.8
MEDIUM 4.4 The Rencontre plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.13.7… wordfence
a68cb059-972f-473d-90cb-41ccda052b08 MEDIUM 4.4 The DebateMaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color options in the plugin s… wordfence
a67972d7-abfd-4ce3-9e47-30736ab32af5
< 2.16.1
MEDIUM 4.4 The Maileon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, … wordfence
a658d150-bcd5-4334-b07a-e09b3995169d MEDIUM 4.4 The Semalt Blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up t… wordfence
a641fdd8-27d9-41e1-bc41-372dda4b2cf5
< 7.5.0
MEDIUM 4.4 The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable t… wordfence
a6320203-2ee8-4316-96bc-0a8e1dd6b66a
< 4.15.15
MEDIUM 4.4 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
a621cd24-d012-40f0-bfac-29268751f772
< 4.1.7
MEDIUM 4.4 The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
← Prev 1293 1294 1295 1296 1297 1298 1299 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top