ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1307 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
882caa58-b56f-455f-ab3e-1fd8fd4e10e2 MEDIUM 4.4 The Circles Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up… wordfence
8810d237-06d5-45a0-8402-a2e7e15418d0
< 2.1.5.6
MEDIUM 4.4 The WP Popups – WordPress Popup builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se… wordfence
88075c15-079f-4de2-8e15-374eb7b8c77b
< 2.1.5
MEDIUM 4.4 The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Header Title'… wordfence
880573d8-6dad-4a1b-a5db-33e1dc243062
< 1.24.0
MEDIUM 4.4 The FiboSearch - AJAX Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin… wordfence
87bd0e6b-7f0d-4696-99aa-c87013efc5a8
< 3.2.0
MEDIUM 4.4 The TNC PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to,… wordfence
87b49bae-05e6-44cd-86a1-8df3249a25f9
< 3.7.3
MEDIUM 4.4 The Popup Like box – Page Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
878a687c-9baf-4cb3-b603-e3dec1eb0544 MEDIUM 4.4 The Google AdSense for Responsive Design – GARD plugin for WordPress is vulnerable to Stored Cross-Site Scripting in v… wordfence
876f0843-c75b-40aa-9e14-9ffbffea6ef6 MEDIUM 4.4 The Affiliate Link Tracker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
86f6e8b8-ebfd-4d9f-a285-9d0aa2e961ff
< 4.0.9.2
MEDIUM 4.4 The MailChimp Subscribe Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ve… wordfence
86f67129-2042-4dff-85de-e189e9f6b53d
< 1.3.44
MEDIUM 4.4 The Contact Form Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
869b8923-d8f9-4a14-89ef-6e8871fa114c MEDIUM 4.4 The Premmerce Product Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
86991143-d4e7-4114-b219-0deedd084858
< 2.45.1
MEDIUM 4.4 The Simple Giveaways plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up… wordfence
86937e94-b6ab-45f6-93c8-1bb786b5732b MEDIUM 4.4 The Draft Notify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5… wordfence
8623d2cc-dcdd-4453-9a86-669bdd44eae1 MEDIUM 4.4 The Short Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'short_link_post_title' and 'sh… wordfence
86079059-11c7-4545-b254-6bf524367b46 MEDIUM 4.4 The Video Contest WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
85c40853-c100-4c5a-a93a-f27b199dba2d
< 2.38.4
MEDIUM 4.4 The Download IP2Location Country Blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
85b439ea-08f9-4b4e-80da-7c5f80bc2818
< 1.0.7.2
MEDIUM 4.4 The WOLF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and in… wordfence
85b2557e-0420-4087-a6d8-1d54fd269261
< 1.4.4
MEDIUM 4.4 The Simple Video Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
85930893-d415-4131-bcda-54a20644eddc
< 7.98
MEDIUM 4.4 The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Import … wordfence
856e27ea-fec2-4805-bc66-f20b83b9610c
< 45.9.0
MEDIUM 4.4 The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up… wordfence
8546cd0b-2d6c-4428-81d5-ffd00540b823
< 4.0.0
MEDIUM 4.4 The Noptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.7 due… wordfence
849888c9-61db-4b94-8140-0cd417a0f362
< 3.6.3
MEDIUM 4.4 The Textmetrics plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.… wordfence
84624efa-4cdb-4d8c-9c98-84c334c02a9b
< 5.7.45
MEDIUM 4.4 The Email Subscribers by Icegram Express – Affordable, Powerful Email Marketing for WordPress & WooCommerce plugin for… wordfence
8426920c-e0df-4a13-9f1f-2d6b6a5ab1ab MEDIUM 4.4 The Flatty plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.0 due… wordfence
834df212-a4da-425f-9c15-358211b5cb54 MEDIUM 4.4 The CodePen Embed Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
← Prev 1304 1305 1306 1307 1308 1309 1310 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top