ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1328 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3cf2013a-d403-456f-aeb4-46b6e00b057f
< 2.8.2
MEDIUM 4.4 The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
3c5349da-90bd-44a8-a61e-acd2c67cca32
< 1.17.0
MEDIUM 4.4 The Photo Gallery – Responsive Image Galleries by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
3c14a863-2aed-4f65-a0e3-eb73e485ce85
< 5.0.9
MEDIUM 4.4 The Slimstat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions … wordfence
3c020d80-b386-40f5-915b-f1d59582c31a MEDIUM 4.4 The Map Categories to Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
3be9ffb4-5614-4a5f-bc2a-38ad626f8e3e
< 1.3.1
MEDIUM 4.4 The CM On Demand Search And Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings… wordfence
3bc98896-6ff9-40de-ace2-2ca331c2a44a
< 2.2.0
MEDIUM 4.4 The Photospace Responsive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘psres_button_size… wordfence
3badf9b8-7558-4a46-9eb2-cd119a77c903 MEDIUM 4.4 The PubyDoc – Data Tables and Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti… wordfence
3baca79e-1234-4b26-998e-574c4ad33d39 MEDIUM 4.4 The Carousel Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up … wordfence
3baa0543-cdfb-4699-97ca-eaa83c2494a1
< 3.1
MEDIUM 4.4 The Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via chat widget settings like 'cht_close_but… wordfence
3b3c2a72-8a8d-4b9a-98e8-f982e34cebb5
< 3.5.2
MEDIUM 4.4 The Popup addon for Ninja Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
3b08f457-0864-41e0-b45e-cbd597d87752
< 6.4
MEDIUM 4.4 The Widget for Social Page Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… wordfence
3af18a17-81a0-4720-b222-153ab4ddf7d9 MEDIUM 4.4 The Testimonials Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version… wordfence
3adf6b20-110f-4057-9fab-5248e9c18555
< 4.7.0
MEDIUM 4.4 The Gallery by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versi… wordfence
3ad7ac46-e7d2-4d0c-ae20-fe9ddabf41b7 MEDIUM 4.4 The ATP Call Now plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0… wordfence
3aca1995-2408-423d-afb6-6cf452fbee37
< 1.1.0
MEDIUM 4.4 The Smoothscroller plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up t… wordfence
3aa2a693-831b-44e7-b158-99fecf6506be MEDIUM 4.4 The Cookies by JM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to… wordfence
3a6fb164-d953-4e0e-80cd-1a99b684ab44 MEDIUM 4.4 The USERCENTRICS CMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
3a6eb99c-bc5e-4b8d-8e4f-496e0b1f44d4 MEDIUM 4.4 The WP Mailto Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
3a68cd5f-3124-42d2-917d-24cb4efa5346
< 1.0.77
MEDIUM 4.4 The Polls CP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,… wordfence
3a65e2e8-f89f-4678-a850-1c8c6804591b MEDIUM 4.4 The Mobi2Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.0 du… wordfence
3a31147b-791c-436f-9407-43485ec2ef50
< 2.0.2
MEDIUM 4.4 The bunny.net – WordPress CDN Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti… wordfence
3a066eae-4040-4d76-b730-47d98dc37662
< 1.0.264
MEDIUM 4.4 The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt data parameter … wordfence
3a044983-1ec7-464b-aa5d-d479be45bb1a
< 2.2.15
MEDIUM 4.4 The EventON plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, … wordfence
39d41772-49f3-4bce-a170-cbe64ba99184
< 4.2.0
MEDIUM 4.4 The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Feed Name value … wordfence
39a3dabb-4c4a-4423-861c-c26c7365185c
< 1.7.4
MEDIUM 4.4 The FAQ Builder AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
← Prev 1325 1326 1327 1328 1329 1330 1331 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top