πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1312 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
74e15c52-4245-41b0-8005-41e9ac2c2edc
< 1.3.6
MEDIUM 4.4 The Widget Post Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
74d3606f-bd62-4844-ac17-8e47feddab92 MEDIUM 4.4 The Login Configurator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions … wordfence
74bf6cb2-318f-4b2a-b79c-729fe09570fe
< 1.3.7
MEDIUM 4.4 The BestWebSoft's Twitter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in vers… wordfence
74b284b7-ec0a-42c1-82e5-0c8cb422c0c5
< 2.16.1
MEDIUM 4.4 The Save as Image plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… wordfence
746e47f2-3fe3-439c-bd54-a9bba9c86271 MEDIUM 4.4 The BlogBuzzTime for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers… wordfence
745cf98c-ad3a-4ec9-9ee8-ae817d5d7358
< 1.0.8
MEDIUM 4.4 The Easy Hide Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up … wordfence
7455901f-ca0b-4b55-811e-76685fe7fd63
< 7.1.12
MEDIUM 4.4 The Stylish Price List – Price Table Builder & QR Code Restaurant Menu plugin for WordPress is vulnerable to Stored Cr… wordfence
743788ed-bd40-4eb4-a27e-d4eb89df3a41 MEDIUM 4.4 The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Form Heade… wordfence
73fd35b4-16b3-4f57-a3e4-46e4de0ee822
< 2.4.18
MEDIUM 4.4 The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
73b55486-adb8-40c6-9113-c98618d9cb00 MEDIUM 4.4 The WP Hello Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'digit_one' and 'digit_two' p… wordfence
73b4e5a2-bf75-4df9-a816-2cc858947c39
< 4.3.3
MEDIUM 4.4 The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via setti… wordfence
7394f468-b1d6-477e-9213-e01c74e2e504
< 3.5.1
MEDIUM 4.4 The WP Coder – Powerful HTML, CSS, JS and PHP Injection plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
7350bb9f-8c75-4292-9769-bccb3805292e
< 1.15.30
MEDIUM 4.4 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Store… wordfence
732f6458-c39f-4e77-8ce6-68d74c67084a
< 1.1
MEDIUM 4.4 The Call Now Accessibility Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via "Button Text" in… wordfence
73232bff-b11a-4580-8cde-5bf085ba749c
< 3.4.5
MEDIUM 4.4 The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
73210f4b-3f4a-4fdc-9d4d-1a97d79f04c0
< 3.2.10
MEDIUM 4.4 The Post Slider and Post Carousel with Post Vertical Scrolling Widget – A Responsive Post Slider plugin for WordPress … wordfence
7319ca86-0575-4d52-9ca2-1527d7394748 MEDIUM 4.4 The Append Link on Copy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
72eb1cd3-47cb-4d9b-9bfd-87fef7859974
< 1.6
MEDIUM 4.4 The Meks ThemeForest Smart Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i… wordfence
72835a3e-e842-4146-ae7d-4aea722de11f
< 1.0.1
MEDIUM 4.4 The Clio Grow plugin for WordPress is vulnerable to Stored Cross-Site Scripting up to, and including, 1.0.0 due to insuf… wordfence
72800e9b-8e2c-4725-9a87-a9b187ad5967
< 15.0.7
MEDIUM 4.4 The cformsII plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,… wordfence
724d8f79-f683-4b06-841d-a9104c87f3c6
< 2.1
MEDIUM 4.4 The Track Geolocation Of Users Using Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… wordfence
722aae99-fcfb-4234-9245-5db57aaa03c5
< 1.6.4
MEDIUM 4.4 The Meks Smart Social Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meks Smart Social… wordfence
7229d6b1-0c11-477c-8569-f5d57930d0d6
< 1.10.1
MEDIUM 4.4 The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
7227749b-a920-41c8-ac3f-249a0e43e089 MEDIUM 4.4 The DOAJ Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.… wordfence
72273368-042d-4ad4-9d1d-ca9c6db9cf3b
< 6.8.4
MEDIUM 4.4 WordPress core is vulnerable to Cross-Site Scripting via client-side template overriding in the admin area in all versio… wordfence
← Prev 1309 1310 1311 1312 1313 1314 1315 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top