πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1315 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6a2dea28-14cf-4e83-ac72-efc7c97ecf54
< 3.0.5
MEDIUM 4.4 The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website … wordfence
6a192e28-45cf-4d6a-ab87-b03d8264e7df
< 2.7.4
MEDIUM 4.4 The Carousel, Slider, Gallery by WP Carousel – Image Carousel with Lightbox & Photo Gallery, Video Slider, Post Carous… wordfence
69d957d3-a0d5-44ec-a9b0-8c9b41175379
< 1.3.0
MEDIUM 4.4 The Livestream Notice plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
69d48695-8165-42bd-b8f7-56c7394bcbcf MEDIUM 4.4 The Goal Tracker for Patreon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
69d3e61f-6aef-45ad-b29d-579fdf005ab7
< 2.1.21
MEDIUM 4.4 The Tealium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.20 d… wordfence
69bbe342-4969-4f82-aacb-7fd7bf65a75c
< 4.2.7.5.1
MEDIUM 4.4 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin sett… wordfence
699d5e15-b638-4447-a367-aa349a330d23 MEDIUM 4.4 The Welcome Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
6985a8bb-0ad5-4b02-9a95-9dbc6018dec0 MEDIUM 4.4 The Category SEO Meta Tags plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
698079d0-b539-431c-98c3-c69d0352d214 MEDIUM 4.4 The Custom More Link Complete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ve… wordfence
692e995d-cdfc-4ab8-8a8a-5423eb7f8d15 MEDIUM 4.4 The Download SpamReferrerBlock plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in v… wordfence
6913ae56-e8a2-40df-ae99-b1957193ccbe
< 2.2.0
MEDIUM 4.4 The Posts Footer Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
68c22e71-c704-44c1-86e6-856f6244393d MEDIUM 4.4 The Simple Long Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
68a520bb-261a-43f0-993d-de208035afe5
< 1.0.28
MEDIUM 4.4 The WP-Piwik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin display name in versions up to… wordfence
68991289-acfa-4ab9-9852-755e5f1eda33
< 4.2.7.2
MEDIUM 4.4 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin sett… wordfence
684e199b-c3c9-47d5-a67e-8f4735eaed84
< 1.8.28
MEDIUM 4.4 The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
6833102f-33fb-419f-869d-b1b6cc9c147b
< 2.6.0
MEDIUM 4.4 The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
67fc59b6-7b6e-4dcb-b86a-c2236cb263f4 MEDIUM 4.4 The Post-to-Post Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
67c495dd-ccff-49ff-91cd-40dd66696401
< 1.3.4
MEDIUM 4.4 The The Tribal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.3… wordfence
6741b770-79d3-4797-8f8f-4ca83fde4705 MEDIUM 4.4 The WP htaccess Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions… wordfence
66fd9aa4-c8ec-42d6-b03a-7534d964e38f
< 1.8.33
MEDIUM 4.4 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
66e78219-b3fd-40e9-a58c-8e27ef3c5e4a
< 1.5.4
MEDIUM 4.4 The Subscribers – Free Web Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad… wordfence
66d217f1-03cf-496d-b3a4-09f9b5bb7966 MEDIUM 4.4 The Configure Login Timeout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
66ca9c39-1ba0-4208-ae35-d2c3c9ea4eb9
< 5.1.20
MEDIUM 4.4 The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner… wordfence
66c90387-af23-48fc-94da-708b9c223fe3
< 1.2.11
MEDIUM 4.4 The Swifty Bar, sticky bar by WPGens plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… wordfence
66c58d4c-8c36-40af-827d-0e86f2110e3c MEDIUM 4.4 The WP Login Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to,… wordfence
← Prev 1312 1313 1314 1315 1316 1317 1318 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top