πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1316 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6696b262-c6e5-4413-b7dc-894965daa5ac MEDIUM 4.4 The salavat counter Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_url' paramet… wordfence
66925385-d89e-45c0-a87b-4ad4f7b89d60
< 25.09.30.1006
MEDIUM 4.4 The Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and i… wordfence
668d4bd3-adde-4347-9169-67c3c96e1743
< 4.0.3
MEDIUM 4.4 The ARMember plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and… wordfence
66518929-d5e7-4b4d-a04c-a96ad0df308c MEDIUM 4.4 The weebotLite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in versions up to, … wordfence
66293047-1d1d-434f-bde6-130197fa93ca
< 1.28
MEDIUM 4.4 The FAQ / Accordion / Docs – Helpie WordPress FAQ Accordion plugin plugin for WordPress is vulnerable to Stored Cross-… wordfence
660f6357-d7bd-45c4-add3-edf83d80aa30
< 4.12.5
MEDIUM 4.4 The Ajax Search Lite – Live Search & Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admi… wordfence
65e76681-80e0-40aa-a68b-87cb0c42b4f8
< 2.3.1
MEDIUM 4.4 The Pinyin Slugs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
659e13bc-c225-4c35-95d5-455d39798bc5
< 4.15.7
MEDIUM 4.4 The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress i… wordfence
655c08e6-4ef2-438e-b381-1bc3748c3771
< 1.3.0
MEDIUM 4.4 The ImagePress – Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… wordfence
655b35a7-a532-4ceb-aa02-4a8192e6449d MEDIUM 4.4 The SVS Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via pricing table settings in a… wordfence
651646b0-231f-401c-9f6d-d414609bd7ba MEDIUM 4.4 The Quiz Organizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin… wordfence
6507c647-0d1e-498c-840a-a72bd3474117
< 4.7.2
MEDIUM 4.4 The WP Maps – Display Google Maps Perfectly with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
64c4c001-1963-437e-9394-cf3ad0e63342
< 9.8.1
MEDIUM 4.4 The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via Text Co… wordfence
64b22728-cb07-48be-94b7-1089156490cd
< 3.9.9
MEDIUM 4.4 The Smush – Lazy Load Images, Optimize & Compress Images plugin for WordPress is vulnerable to Reflected Cross-Site Sc… wordfence
644290f8-24f0-425c-b114-ef464daedc84
< 5.5.4
MEDIUM 4.4 The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
64371d43-3acd-4863-80e4-deab071777b9
< 10.2.4
MEDIUM 4.4 The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜Feed[title]’ parameter in … wordfence
6435fc6b-a5dc-4de3-9c53-5d1bfe8cfd88 MEDIUM 4.4 The Random Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
64225f1c-3981-4bae-bb6a-95d1a27ad6aa MEDIUM 4.4 The WP Twitter Mega Fan Box Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
63c681e5-3110-4790-a075-4996fa1f2129 MEDIUM 4.4 The Article Directory Redux plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in vers… wordfence
63a373a5-4284-4de5-93cd-63274b4e739f
< 1.100.0
MEDIUM 4.4 The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s… wordfence
639a46b3-d19f-4ab4-995e-fd3de556b76e MEDIUM 4.4 The MojoPlug Slide Panel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version… wordfence
636731ab-31e6-4750-b691-4850b29022dc
< 1.8.8
MEDIUM 4.4 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
633d6921-eece-4e7a-8ed8-48b7c579b5ed
< 1.3.5
MEDIUM 4.4 The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable t… wordfence
6322ba0b-e1f1-4fda-b7a4-826844046f89
< 1.5.2
MEDIUM 4.4 The Smart Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
631fc709-98e8-4655-96fc-c37717705a80
< 16.3
MEDIUM 4.4 The USM Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … wordfence
← Prev 1313 1314 1315 1316 1317 1318 1319 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top