πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1298 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a38004fe-828f-40bb-9ae7-583642e41dfd MEDIUM 4.4 The AWSOM News Announcement plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
a37f049d-e704-4139-b311-51acbd373df7 MEDIUM 4.4 The BMI Adult & Kid Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
a375da2f-f074-4b03-af5b-2a4c2853cc58
< 4.15.7
MEDIUM 4.4 The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress i… wordfence
a2f9eed8-9656-48a2-9414-2cfdd3ebb059 MEDIUM 4.4 The Filterable Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver… wordfence
a2f378dd-d8de-445e-9c54-d07627e9c0e9
< 4.15.20
MEDIUM 4.4 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
a27b8d53-7229-4c88-9bda-5db31b0f8d92
< 3.4.9
MEDIUM 4.4 The Terms descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
a26c71d6-9840-450e-90cd-c20de53f5cb5
< 12.0.6
MEDIUM 4.4 The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… wordfence
a256e11e-b59d-4ce1-ac52-da89789e97a9
< 1.7.8
MEDIUM 4.4 The Simple Post Notes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
a24ed885-557b-4f3e-b3d0-345d2ebc8cc5
< 20240412
MEDIUM 4.4 The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
a2362dea-8c4a-426f-9482-b7e19b8f5f4e
< 0.5.1
MEDIUM 4.4 The Extra User Details plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions … wordfence
a22bba3e-423a-4231-833b-c0be57a3bf7b MEDIUM 4.4 The Electric Studio Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin se… wordfence
a219a232-5ff4-4855-8f29-437ed26b4f34 MEDIUM 4.4 The Article Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'publish_terms_text' adm… wordfence
a2121e1a-88f4-41b9-9a72-fe263b4739ef
< 5.2.1
MEDIUM 4.4 The Gianism plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, … wordfence
a15cc96b-2af2-4a7d-af61-633d13b71b49 MEDIUM 4.4 The WP Backpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
a14b0f3d-7c18-4468-88f7-cc070c4cea4e MEDIUM 4.4 The MeetingList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
a10ee756-1b71-4232-817c-1ba6ead7f0f0
< 1.6.2
MEDIUM 4.4 The Mobile Call Now & Map Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i… wordfence
a108f8bf-a77c-4f29-a63b-c535a054dcaf
< 1.2.6
MEDIUM 4.4 The Coupon & Discount Code Reveal Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings … wordfence
a0f877c3-cb51-4b82-ae7a-a30c90d593f7
< 1.15.34
MEDIUM 4.4 The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
a0f701d4-8cae-4771-8233-bb94a87a770e
< 5.7.1
MEDIUM 4.4 The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to HTML Injection in all versio… wordfence
a0c962ba-43ef-4713-acd9-1e499f857df8
< 2.1.0
MEDIUM 4.4 The Tracking Code Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
a0c04f12-7602-4d57-aa0c-54ecbf7f8875 MEDIUM 4.4 The WP Custom Cursors | WordPress Cursor Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad… wordfence
a0829035-7782-456d-acd5-639051d7ebc3
< 1.4
MEDIUM 4.4 The Backend Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
a070f19e-9f65-499d-87c0-65be12d4be84
< 1.0.5
MEDIUM 4.4 The Experto Dashboard for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
a04e5086-1ddc-4618-90fe-2cd6e6d232c4
< 2.7
MEDIUM 4.4 The WP Thumbtack Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
a04652bc-f815-4840-b791-3fb12d3b4f7c MEDIUM 4.4 The CF7 File Download – File Download for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad… wordfence
← Prev 1295 1296 1297 1298 1299 1300 1301 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top