πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1319 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5bf4ffaa-5192-4fb6-95d0-d19c4fe45b93 MEDIUM 4.4 The Chat Bee plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and… wordfence
5bde2c99-9ef9-4303-9d02-dd7305674bf0
< 3.39.5
MEDIUM 4.4 The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Stored Cross-S… wordfence
5b97a2f7-b730-4fb7-a41e-dd37f5f87f27
< 1.8.7
MEDIUM 4.4 The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_foote… wordfence
5b6739b5-0df4-49b2-a655-4f0cff5886b7
< 5.0.3
MEDIUM 4.4 The Float menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, a… wordfence
5b28a733-2459-46f0-87c3-1a573a8cd55e
< 4.5
MEDIUM 4.4 The Simple Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.4… wordfence
5b12f597-c34c-4b3b-80a6-8fd25f60b862
< 2.1.2
MEDIUM 4.4 The WP Datepicker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
5aca31f5-310f-441b-8d8c-51b7bf2b0b7d
< 1.8.4
MEDIUM 4.4 The Fetch JFT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to… wordfence
5ab9c383-14da-479d-9709-1ae154dae398
< 4.6.10
MEDIUM 4.4 The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions… wordfence
5a9746d0-6a0b-47cf-b9fa-246af6b54323 MEDIUM 4.4 The Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension plugin for WordPress is vulnera… wordfence
5a7e9889-6b3e-41c6-a09e-5fcc5351b7cb
< 4.15.7
MEDIUM 4.4 The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress i… wordfence
5a69f51e-0bac-4b2e-8ad4-597c6fbbff83
< 9.7.1
MEDIUM 4.4 The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
5a604c8d-1e4a-42c2-b7cf-ee6cae54730c
< 1.3.0
MEDIUM 4.4 The TWIPLA (Visitor Analytics IO) – Privacy-First Website Stats, Session Recordings, Heatmaps, Polls and Surveys plugi… wordfence
5a4eeb77-7a8b-489f-8ded-bbe09e881758 MEDIUM 4.4 The WP Roles at Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ver… wordfence
5a40bac7-d3b8-486d-938a-30591ff3016c
< 3.8.7
MEDIUM 4.4 The Popup Box – Best WordPress Popup Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admi… wordfence
59fa2539-c1df-4c01-b57f-b7b4bde8537f
< 2.5.3
MEDIUM 4.4 The CYAN Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
59f7a1b2-f718-40e7-8030-b9212edf71b7
< 1.1
MEDIUM 4.4 The Formilla Chat and Marketing Automation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Fo… wordfence
59e60d00-985e-4152-a3d8-d2ba8075fab8
< 3.5.0
MEDIUM 4.4 The Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Pop… wordfence
59dc2448-491c-478f-a784-c727057b126b
< 4.1.1
MEDIUM 4.4 The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… wordfence
59b9c2f8-f84a-49f9-98c5-6ef90475d686 MEDIUM 4.4 The Breaking News WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
5975a107-8083-4f9e-b2b2-8c6ae1ac8f39 MEDIUM 4.4 The itemprop WP for SERP/SEO Rich snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s… wordfence
58ee5f31-7d10-4772-929c-98249a351342
< 5.0.3
MEDIUM 4.4 The Custom post types, Custom Fields & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin … wordfence
5853aa0c-09cf-4af8-b75a-4ec95dfe94c3
< 3.32
MEDIUM 4.4 The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored … wordfence
583b5cd7-a33e-41d0-a389-ac36679d5f22 MEDIUM 4.4 The Client Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Testimonial Hea… wordfence
57f413f2-8fca-4472-9658-7aac4657033c MEDIUM 4.4 The AuthorSure plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3 d… wordfence
57dda8e6-54d1-41db-a54d-4a5d635e23b7 MEDIUM 4.4 The Easy Event calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
← Prev 1316 1317 1318 1319 1320 1321 1322 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top