πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1320 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
57a7a8cc-6a59-4e92-8e14-36e2550b0f51
< 3.2.0
MEDIUM 4.4 The One Click Accessibility plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
57953bab-7430-4841-b073-7db7964e6a65
< 2.4.0
MEDIUM 4.4 The Seed Fonts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version 2.3.1 du… wordfence
578ed437-98b7-495b-91fd-45b882f39d95
< 1.6.5
MEDIUM 4.4 The Meks Smart Social Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… wordfence
5786b859-3ee9-45ab-8926-f4a09e323e3b MEDIUM 4.4 The Comments Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
577d8986-edc5-445f-80cf-7a7f2cca9749
< 1.7.62
MEDIUM 4.4 The Unite Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in versions… wordfence
575c3329-8dbb-4d15-8e11-a86a01b96f50 MEDIUM 4.4 The Extended Random Number Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin se… wordfence
575743cc-6399-4f1d-893c-3fb9d4a98738 MEDIUM 4.4 The WP Back Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … wordfence
572fe891-5845-4a1c-ad3e-ddf5c54af5ba
< 6.8.4
MEDIUM 4.4 WordPress Core is vulnerable to Stored Cross-Site Scripting via admin settings in various versions due to insufficient i… wordfence
56bdf884-425c-40f9-88b5-66ed4c0f0501
< 1.9.2.3
MEDIUM 4.4 The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress i… wordfence
56ab6429-4b1b-461a-9fcd-b4be84985118
< 3.10.5
MEDIUM 4.4 The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cros… wordfence
5655d60b-cfd6-40b3-ad64-81db4c54ab3f
< 4.3.0
MEDIUM 4.4 The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
5652f148-5247-4b15-bd86-653267d95fbf
< 4.7.8
MEDIUM 4.4 The Button contact VR plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
55fac183-bd8d-4e16-b25a-784861897deb
< 1.2.5
MEDIUM 4.4 The Paid Memberships Pro - Courses for Membership Add On plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
55f8d7e6-7bcd-4556-932b-7bf422db0b39
< 3.3.4
MEDIUM 4.4 The FancyBox for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versi… wordfence
55f4a1b5-2ff1-4abd-b89d-6a3aa921a24b MEDIUM 4.4 The Simple Video Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
550c3f56-d188-4be1-82cd-db076c09cf61
< 2.5.2
MEDIUM 4.4 The File Renaming on Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ver… wordfence
54b65d91-be44-4596-be23-5a9e1d4d66dd
< 2.2.7
MEDIUM 4.4 The WP Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, … wordfence
54b15b0e-2d85-4ea9-ac71-fb56c8f05f3b
< 1.4.4
MEDIUM 4.4 The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
547c425d-8b0f-4e65-8b8a-c3a3059301fe
< 1.0.1
MEDIUM 4.4 The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Title… wordfence
542831f3-1e32-4761-b3a6-a5fd90213bbc MEDIUM 4.4 The Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme plugin for WordPress is vulnerable to St… wordfence
541dae6d-209b-4216-ab7a-ddcd71a322cb
< 3.0.0
MEDIUM 4.4 The WP-Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.77.3 … wordfence
540fef7f-8952-4525-9d07-fe3b3d777359
< 2.0.18.1
MEDIUM 4.4 The WP Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
54019f42-488d-484f-b34e-2b5bd5b0a1dd
< 1.7.15
MEDIUM 4.4 The Slick Popup: Contact Form 7 Popup Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the m… wordfence
53de68ad-76a6-4043-8369-7679c1c5c1cd MEDIUM 4.4 The WP Simple Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up… wordfence
5381b629-59f0-4b06-b23e-c38638afea0b
< 1.22
MEDIUM 4.4 The TGG WP Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
← Prev 1317 1318 1319 1320 1321 1322 1323 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top