πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1308 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
834bedf0-a2bc-4396-a160-3d3f399c1897
< 3.2.99
MEDIUM 4.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
833eb481-4fb4-432e-8e93-3f497ccbf1eb
< 7.6.1
MEDIUM 4.4 The Wordfence Security – Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
82f5e976-2564-4f8b-96d5-cfac9945737c MEDIUM 4.4 The Call Now Icon Animate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in versi… wordfence
82eb759f-e8d5-40c6-998f-f6981d9d6644
< 4.4.8
MEDIUM 4.4 The Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor plugin for WordPress is vu… wordfence
82862fc6-a542-4329-b9fd-e69f18288ac4
< 5.8009
MEDIUM 4.4 The Ebook Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.80… wordfence
8283a502-6fb8-43ff-8f46-8afbfdbb22f7
< 3.7
MEDIUM 4.4 The BSK Forms Blacklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers… wordfence
8243b65b-8340-404d-90cb-5706fb239dc2
< 6.2.3
MEDIUM 4.4 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
823d7145-2347-4a07-b756-2dfc7878456e MEDIUM 4.4 The Post Custom Templates Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
821f4ea9-bc25-4d65-9058-5b77c4f1b230
< 1.6.3
MEDIUM 4.4 The CM E-Mail Blacklist – Simple email filtering for safer registration plugin for WordPress is vulnerable to Stored C… wordfence
81e26924-c9eb-4ddf-89e3-a8bf95d23b78
< 5.0.4
MEDIUM 4.4 The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
81b8451a-e5b8-44e9-8253-48beb2a43e6d
< 16.26.12
MEDIUM 4.4 The WP-Recall plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to… wordfence
81a2c94c-712a-4f72-842e-acb97abb4ea7
< 2.1.7
MEDIUM 4.4 The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al… wordfence
81936c52-feb7-4f10-940d-cfce5963f400
< 3.3.8.1
MEDIUM 4.4 The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜gtitle’ parameter (as part … wordfence
818b2547-844d-4667-acc7-66843ca28cfe MEDIUM 4.4 The WooCommerce Parcelas plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
814fcd67-9788-4392-8910-7a2bc8782fd8
< 1.6.5
MEDIUM 4.4 The Short URL plugin for WordPress is vulnerable to stored Cross-Site Scripting via the 'url_externe' parameter due to i… wordfence
80e9aa1f-166f-47df-bc50-c7dd55c6e7cc
< 2.0.4
MEDIUM 4.4 The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unspecified par… wordfence
80ba732f-b3cc-4b42-8c56-9fa1cee08c7b
< 3.8
MEDIUM 4.4 The Best Contact Management Software plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "No Acces… wordfence
80b03e81-6660-483a-9150-e6075b7bffbd
< 2.5.0
MEDIUM 4.4 The PostmarkApp Email Integrator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settin… wordfence
80afca9d-8f9c-412f-b2dd-f0078ec8173c
< 2.1
MEDIUM 4.4 The Cookie Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
800b1a44-4173-4b8e-bc69-9a64218e64d6
< 2.11.1
MEDIUM 4.4 The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App I… wordfence
7fe3e55e-7286-4d12-b24f-fce69248a446
< 2.5.21
MEDIUM 4.4 The Kanban Boards for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
7fd9bb08-1093-4ccd-9817-052760c19588
< 3.1.0
MEDIUM 4.4 The Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Pop… wordfence
7fba4d55-b9fd-4d02-9a86-1ca2130e8ba0 MEDIUM 4.4 The Easy WP Tiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1 … wordfence
7fb42402-4cd8-4d5d-b95a-47076ace27c0
< 2.1.10
MEDIUM 4.4 The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions… wordfence
7fabdf42-4608-4182-aaa9-ba6ef0b3f001
< 1.9.4
MEDIUM 4.4 The Maps Plugin using Google Maps for WordPress – WP Google Map plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
← Prev 1305 1306 1307 1308 1309 1310 1311 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top