πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1327 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
401eeb23-bf43-49a8-9c39-4fcd0db57cd3
< 2.3.1
MEDIUM 4.4 The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via parameters and attributes such as '… wordfence
40156caa-7b73-4b4d-825c-bd3e58ea3ff3 MEDIUM 4.4 The Easy Page Transition plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
400dde23-eafb-4ace-8b4a-ac88d0b200ac MEDIUM 4.4 The WC Captcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
40005aed-07aa-44da-a06e-0187931105ec MEDIUM 4.4 The Sitemap Index plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to… wordfence
3fe3fa95-cc1d-469b-8a97-37987b9ae362 MEDIUM 4.4 The OPEN-BRAIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' settings field in all… wordfence
3facf09f-2e5d-42d0-b0b3-3aea93febe48
< 3.5.1
MEDIUM 4.4 The Simple Share Buttons Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… wordfence
3f9592d1-73a0-422e-b6d2-c31cc79a1a90 MEDIUM 4.4 The Viral Signup – limited opt-in with viral refferal sharing plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
3f56338f-1687-42c3-8fe2-f62fe962eefd MEDIUM 4.4 The WordPress Jitsi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al… wordfence
3f54f117-0dde-49f9-8014-7650bc1a00ac
< 4.6.9
MEDIUM 4.4 The Order Minimum/Maximum Amount Limits for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
3f2504ba-9432-429f-8476-a994f48836c9
< 3.59.9
MEDIUM 4.4 The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Stored Cross-S… wordfence
3f1df412-86cd-4ebc-913b-674cc3b8d89a
< 4.7.1
MEDIUM 4.4 The WP ULike – Most Advanced Marketing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a… wordfence
3eece451-65a3-4c9d-a8eb-05f6f3e2d1d5 MEDIUM 4.4 The Fast Custom Social Share by CodeBard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set… wordfence
3ee86d33-5a1e-4dc5-b2f6-0beffd8a6b2e
< 7.8.6.7
MEDIUM 4.4 The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is… wordfence
3ed1c2a2-54ee-4dc8-a54d-01d7a6dbc22e
< 4.6.1
MEDIUM 4.4 The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings on the 'language' ta… wordfence
3ec6faa4-d8d3-4c5e-91b2-142164d3b481 MEDIUM 4.4 The Font Farsi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
3e75cdd9-54cb-46de-8647-b92831324774 MEDIUM 4.4 The Master Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… wordfence
3e72644c-138d-4733-bcca-a8305273d1a0
< 2.6.0
MEDIUM 4.4 The Fleet Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
3e374887-0062-4ca2-8e43-13a6c4207f84
< 2.6.4
MEDIUM 4.4 The YouTube Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
3e1864e7-bd3b-431f-9a9d-378b376298f9 MEDIUM 4.4 The enigma-chartjs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in version… wordfence
3e0f7fa4-2d0d-4206-a3ff-97bf95c84808
< 1.2.3
MEDIUM 4.4 The AI Chatbot for WordPress – Hyve Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… wordfence
3dde3216-e0a9-463f-87e8-b71552d2f3b2
< 1.11.4
MEDIUM 4.4 The Cooked plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.11.3 du… wordfence
3dbe7a3c-8247-4f1f-aca6-dda4bdcc1daf
< 10.0.3
MEDIUM 4.4 The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 10.0… wordfence
3db97180-9308-4891-9de9-acefe31d088f
< 4.3.0
MEDIUM 4.4 The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in ver… wordfence
3d40498a-b0d4-4304-bab7-e9620ef61db5
< 2.94.10
MEDIUM 4.4 The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
3d0da23a-12e6-4e57-8413-dc86a62b1800 MEDIUM 4.4 The jwp-a11y plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,… wordfence
← Prev 1324 1325 1326 1327 1328 1329 1330 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top