πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1321 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
53760acf-e8b2-4e35-8c01-768472fc0996
< 1.6.1
MEDIUM 4.4 The Simple Table Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version… wordfence
5344499d-c183-4164-a52c-0dca7873f63d
< 2.0.8
MEDIUM 4.4 The Woocommerce Vietnam Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… wordfence
53192f38-ab76-4843-a652-37c266b527e7
< 4.9.65
MEDIUM 4.4 The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
530ee998-de16-407f-8e84-b0d7c31c6f5f
< 1.5.12
MEDIUM 4.4 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se… wordfence
52f9db86-7fed-4b32-8384-3ceb300f9249
< 2.5.8
MEDIUM 4.4 The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
52f98de0-ad91-4b5a-91ef-6fe705f2bf60 MEDIUM 4.4 The Flattr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, a… wordfence
52f1f545-d2bf-4692-a1f2-10847348e862 MEDIUM 4.4 The Ninja Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
52e452d4-31ae-4909-a653-4f69b7e1c32a MEDIUM 4.4 The Amazon Product in a Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
52983bf6-908a-4287-b89e-cd09b4c48efe MEDIUM 4.4 The Dovetail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and… wordfence
5256a249-b355-480d-a532-5931e4dea481
< 2.5.9.4
MEDIUM 4.4 The Namaste! LMS for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and in… wordfence
52538617-a1d1-40ed-8321-e39d06869398
< 2.1.2
MEDIUM 4.4 The All-in-one Floating Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… wordfence
524e9ec1-9c7c-4b06-915c-8122ea6c3601
< 5.16.0
MEDIUM 4.4 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin sett… wordfence
521af15c-983c-49dc-a90b-b090281db78a
< 1.2
MEDIUM 4.4 The NinjaTeam Header Footer Custom Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via CSS styles… wordfence
52056177-8604-48b9-ab50-d0dc1e13a3d5
< 2.16.1
MEDIUM 4.4 The Save as PDF plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
51b42108-5b6d-4d41-b663-cccab8b552be
< 2.4.1
MEDIUM 4.4 The Request a Quote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions… wordfence
513124f6-ea14-46ca-94c5-f9fa15b19d8c
< 4.4
MEDIUM 4.4 The Social Share Buttons & Analytics Plugin – GetSocial.io plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
512c9a2f-b023-4e28-8dd8-35795e68a8b3 MEDIUM 4.4 The Postalicious plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
51156188-83f2-48ef-89cb-0caa488c6366
< 3.2.2
MEDIUM 4.4 The Save as Image Plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… wordfence
50ea2a0f-4ebe-4add-9f13-895790c92001
< 8.7.1
MEDIUM 4.4 The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the preheader_text value in version… wordfence
50d8dc95-4a60-4a1a-bb9f-ba48b58d868e MEDIUM 4.4 The Accordion – Multiple Accordion or FAQs Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
50d190cb-f2c8-4cd9-844b-98b298a292a0
< 1.1.73
MEDIUM 4.4 The Payment Form for PayPal Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
50affe4f-d27e-4ead-a14b-abf792d5f0f0 MEDIUM 4.4 The Sticky Social Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
5084afcc-b6fc-4d89-9ad7-c4ea3e4dae82
< 4.0.0
MEDIUM 4.4 The SoundCloud Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver… wordfence
506a7351-07b9-4c0f-86c3-edfe04bac64c MEDIUM 4.4 The Slidorion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to… wordfence
5061e0be-1785-476a-9528-d6f95656bd61
< 2.0.0
MEDIUM 4.4 The MarketKing β€” Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Stored Cr… wordfence
← Prev 1318 1319 1320 1321 1322 1323 1324 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top