🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1313 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
718dc94c-1f4f-4b5a-969b-d98cabbbe6d8
< 1.7.72
MEDIUM 4.4 The PWA for WP – Progressive Web Apps Made Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… wordfence
717e77b7-8b42-4fca-b288-2415db2d68e6
< 1.8.11
MEDIUM 4.4 The Slider by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers… wordfence
71550a11-20f4-46fa-8b2a-8d3789db4697
< 1.13.4
MEDIUM 4.4 The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… wordfence
71548a7f-43a5-4f71-8add-45f675e8aa66
< 2.2.4
MEDIUM 4.4 The Enhanced WP Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ver… wordfence
70e227a5-fc33-4ff2-a843-ef9484707ae7 MEDIUM 4.4 The NS Coupon to Become Customer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settin… wordfence
70bc58a7-8de3-4d3e-b8f3-b422d4af8d4b MEDIUM 4.4 The Draft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0.9 due … wordfence
705d11b1-0924-46ae-a6e6-8fab16a4df00
< 1.0.2.3
MEDIUM 4.4 The wordpress publish post email notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admi… wordfence
704f9077-61c1-4105-80e6-906fe6bdddc6
< 2.0.67.1
MEDIUM 4.4 The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all version… wordfence
703e251f-734d-4a7d-8b67-897aa6986b8c
< 1.0.3
MEDIUM 4.4 The User Notes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.2… wordfence
7016cd09-ce5b-45cd-8064-f1e836502aab MEDIUM 4.4 The Coronavirus (COVID-19) Notice Message plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se… wordfence
700e9d1c-a178-4033-8607-652178860211 MEDIUM 4.4 The WP Allowed Hosts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allowed-hosts' parameter… wordfence
6fc15a59-e555-450b-836e-5c3d52451b12
< 1.3
MEDIUM 4.4 The Simple Spoiler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … wordfence
6fbcab49-5765-497b-a98e-d87c5b468b11
< 1.7.0
MEDIUM 4.4 The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
6f54fb59-03c1-45e9-a498-1fa1409c4466
< 1.5.5
MEDIUM 4.4 The Pretty Url plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, a… wordfence
6f500eb7-64a2-4734-9688-fbae84f280bc
< 4.15.7
MEDIUM 4.4 The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress i… wordfence
6f34b94f-ea72-4a42-abea-2f2eb565ffdd
< 1.27.0
MEDIUM 4.4 The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-S… wordfence
6ed8f004-f68d-40fb-bca1-b0b92cf24fdb
< 4.3.1
MEDIUM 4.4 The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘qlcd_wp_chatbot_email_sub’ pa… wordfence
6eb099c3-f6f6-4d9c-a9c7-fa1b81ce082e
< 3.6.3
MEDIUM 4.4 The Telegram Bot & Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versi… wordfence
6e7dedc2-5ba1-49c7-9afe-f55023f24e47 MEDIUM 4.4 The SiteNarrator Text-to-Speech Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
6e7c629f-e9c6-4254-ba37-46de5206d77d
< 1.2.2
MEDIUM 4.4 The Booking and Rental Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in v… wordfence
6e7bfd20-a58d-4641-a2d2-6b43c5a2165e MEDIUM 4.4 The «Подсказки» от DaData.ru plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
6e371cb0-b393-486c-8940-515612860417
< 3.12.0
MEDIUM 4.4 The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
6e0d931d-91ff-4088-a183-a9497991de05 MEDIUM 4.4 The Broadly for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
6df68d66-7294-4dff-8ba8-394932a64281 MEDIUM 4.4 The Layer Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
6df29b14-0c9d-4ecf-96be-8c39c93121e2
< 6.6.4
MEDIUM 4.4 The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers… wordfence
← Prev 1310 1311 1312 1313 1314 1315 1316 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top