ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1311 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
77fa042d-1e4f-4344-bf5a-3860add7aae3 MEDIUM 4.4 The Carrot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and i… wordfence
77a923d5-b73e-45cf-9617-09b4d5c8bb5a
< 1.2
MEDIUM 4.4 The Bit Assist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, a… wordfence
779df91d-bf27-42ac-9445-13a4ad63a322 MEDIUM 4.4 The COVID-19 (Coronavirus) Update Your Customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… wordfence
77876d74-5825-4bd8-812e-87061d0470e6
< 6.1.8
MEDIUM 4.4 The Advanced Custom Fields PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in v… wordfence
776a441b-1bb8-46ea-9884-4abf562f6e5c
< 2.7.12
MEDIUM 4.4 The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
771da808-8962-46a3-8519-85d9422583f6 MEDIUM 4.4 The Advanced Social Pixel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio… wordfence
770c64d3-3cc8-4fd9-91d6-96a1c252265a
< 4.7.2
MEDIUM 4.4 The WP Maps – Display Google Maps Perfectly with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
76b4e3d1-170c-4fe0-8e84-246b973d48b1
< 1.8.4
MEDIUM 4.4 The Slideshow Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
76b25ae3-b813-4e79-a5e3-0af5e6eb8a06 MEDIUM 4.4 The Platinum SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
765b09ef-dd6d-4c4e-a381-7bb0dc8d6652
< 1.2.1
MEDIUM 4.4 The Easy Form by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up… wordfence
762190dc-cd19-4bc1-8204-9219881d95e9
< 11.1.2
MEDIUM 4.4 The Disqus Conditional Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin options such as… wordfence
760f46b9-23a2-4f30-be40-abb29b096c01 MEDIUM 4.4 The CSV Importer Improved plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
75ffafcc-7126-410d-b800-b249c03885a8
< 2.6.0
MEDIUM 4.4 The WP Discord Invite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
75f45345-216e-48a8-b131-672aa12a0e0f
< 2.7.22
MEDIUM 4.4 The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a… wordfence
75e89574-a0d4-4383-a6f8-bf977e2ffe4d
< 2.0.0
MEDIUM 4.4 The Simple Image Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via popup settings in versions … wordfence
75da660b-04c7-4f15-b49d-2aa320ef5b4b
< 1.0.13
MEDIUM 4.4 The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin … wordfence
75b8fce9-023d-4603-9d92-46a053d16291
< 5.2.62
MEDIUM 4.4 The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
759add85-3d72-46d5-a973-dd8dcfb9f336
< 5.0.6
MEDIUM 4.4 The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all v… wordfence
758b7c61-92cc-4100-b04a-e5ff6c90f779
< 1.8.1
MEDIUM 4.4 The Safety Exit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.… wordfence
75824b96-8674-4340-9e56-b0cb0f52503d
< 1.4.6
MEDIUM 4.4 The Robokassa payment gateway for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admi… wordfence
756810c0-d805-4391-a67b-19b40597d219 MEDIUM 4.4 The Yandex.News Feed by Teplitsa plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… wordfence
755c8863-33c2-47aa-880a-0ef8b2d594a3 MEDIUM 4.4 The Toggles Shortcode and Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’… wordfence
750a4a94-458c-4944-a99b-a1c8e23e57d1 MEDIUM 4.4 The Sticky Ad Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via numerous plugin options paramete… wordfence
74f212b1-9f70-44c8-a7bb-ee8887be9ea6
< 4.0.9.8
MEDIUM 4.4 The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cr… wordfence
74ea8f1e-d6ff-4a32-b8bf-5d4c8e69433e MEDIUM 4.4 The Flyzoo Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … wordfence
← Prev 1308 1309 1310 1311 1312 1313 1314 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top