ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1297 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a6202c51-c976-4e32-8846-43ac1aae9331
< 3.3.63
MEDIUM 4.4 The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a… wordfence
a61a8d8b-f22f-4a16-95f6-6cf52cf545ad
< 12.3.16
MEDIUM 4.4 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… wordfence
a600f164-7255-4590-8239-2d3e0b445e79
< 3.1.8
MEDIUM 4.4 The WP Adminify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … wordfence
a5f29f35-da79-4389-a0a5-a1be0b0b8996
< 1.6.5
MEDIUM 4.4 The Short URL plugin for WordPress is vulnerable to stored Cross-Site Scripting via the 'comment' parameter due to insuf… wordfence
a5e803ed-6dfb-4845-8efe-addaea89029f
< 7.2.1
MEDIUM 4.4 The Auction Nudge – Your eBay on Your Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
a5e6b508-35ef-45da-bf17-c038d3b7ce52
< 1.7.17
MEDIUM 4.4 The Multi Step Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions… wordfence
a5e0acda-b76e-4290-8546-5da7e7758968 MEDIUM 4.4 The IFrame Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… wordfence
a5dbcc22-ab2e-4114-a7d7-bac01a5c5b3f
< 2.5.6
MEDIUM 4.4 The ApplyOnline – Application Form Builder and Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
a5cb5ab0-2110-49be-bc09-6847065a9dd9
< 3.1.50
MEDIUM 4.4 The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerabl… wordfence
a5cb1fea-134f-4c81-8f2f-76ee42df7f77
< 1.5.61
MEDIUM 4.4 The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
a5a1251c-5f70-4432-953a-cad2ee18b98e
< 5.3.1
MEDIUM 4.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
a56772fd-f77f-4ba5-b5c4-79ac8204b599 MEDIUM 4.4 The Chat Bubble – Floating Chat with Contact Chat Icons, Messages, Telegram, Email, SMS, Call me back plugin for WordP… wordfence
a5436d14-cbb5-420f-9f3a-698ce59c1e1e
< 1.1
MEDIUM 4.4 The Formilla Chat and Marketing Automation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'F… wordfence
a524591b-633e-44c2-9a29-534b612d4ec7 MEDIUM 4.4 The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
a52015fe-c4df-46a6-8f23-b33730797f4c
< 2.5
MEDIUM 4.4 The Participants Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio… wordfence
a5121436-f3cc-4298-8ae6-bfebaac960c3 MEDIUM 4.4 The NS Maintenance Mode for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
a4eca8f3-0b5d-4449-ba89-37c1b497c4d3 MEDIUM 4.4 The Zalomení plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to… wordfence
a4d94570-6652-4614-b686-a6591873889f
< 5.2.64
MEDIUM 4.4 The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
a472e78c-ebd7-4ab8-9b47-96c526754387
< 3.0.13
MEDIUM 4.4 The Tapfiliate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … wordfence
a4701003-26b9-4ed2-bc5a-e160af2b7664
< 3.0
MEDIUM 4.4 The Inspectlet - User Session Recording and Heatmaps plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… wordfence
a469a2cb-1011-4d47-95d2-0b895f24ae8f
< 1.2.8
MEDIUM 4.4 The ReCaptcha Integration for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
a4572874-afd4-4e46-8a28-76a0a6cc8acb
< 1.2.3
MEDIUM 4.4 The Pagination by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ve… wordfence
a43c685b-28d4-425c-984a-f8410c07a469 MEDIUM 4.4 The Beam me up Scotty – Back to Top Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
a3ae55ad-b192-4dde-8a7c-3a4fd71d3475
< 5.1.5
MEDIUM 4.4 The All-In-One Security (AIOS) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via log files in versi… wordfence
a3839c47-5fd0-48e7-9637-d40bd237e122
< 1.3.16
MEDIUM 4.4 The JSON Content Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
← Prev 1294 1295 1296 1297 1298 1299 1300 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top