πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1329 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
399109be-7efe-428e-a9b8-7a68864b2790 MEDIUM 4.4 The CT Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … wordfence
3971c145-6dca-49af-bbb3-7ef4ce51507f
< 1.3.3
MEDIUM 4.4 The Optin Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … wordfence
3924b6f4-75ba-4ee8-b02f-a23fbd24ed67
< 3.10
MEDIUM 4.4 The WP Email Capture plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up… wordfence
38e536a5-b538-498c-b19d-adda36f76164
< 7.32
MEDIUM 4.4 The StopBadBots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … wordfence
38bd6efd-41d5-4bb1-982c-31d20b4c0a1d
< 2.3.4
MEDIUM 4.4 The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
38b8151f-4938-4101-9886-783f54984d20
< 3.2.0
MEDIUM 4.4 The WP-Stateless – Google Cloud Storage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sm'… wordfence
387e1998-f6b1-4a9f-86a8-cd0b10202df6
< 1.8.3
MEDIUM 4.4 The Easy Age Verify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions… wordfence
3870fe43-bece-4a3c-99cf-03393beab78a
< 2.1.4
MEDIUM 4.4 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
3861f675-1a26-4947-91ef-8ab04646704f
< 4.2
MEDIUM 4.4 The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up … wordfence
383a49c2-3239-44ee-b36b-116b73dce9f2
< 3.79
MEDIUM 4.4 The MyCurator Content Curation plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
381ec612-2086-4925-98cd-652a6c2ac081
< 2.0.5
MEDIUM 4.4 The Everest Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
3813c6f3-c385-4811-a126-8607b9097bcc
< 2.6.8
MEDIUM 4.4 The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme plugin for Wo… wordfence
380024dc-ed2a-4a7b-b5f8-47879ad2d659 MEDIUM 4.4 The WP Default Feature Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ver… wordfence
37eb77ed-0b2e-46ea-806d-8041742eab5d
< 4.68
MEDIUM 4.4 The SP Project & Document Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin sett… wordfence
37da32e4-48a1-4830-a47c-c454d60c9811
< 4.15.7
MEDIUM 4.4 The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress i… wordfence
37cf63e3-9301-441d-9852-b2de83078b51 MEDIUM 4.4 The Google CSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
37be9612-fd5c-40dc-9853-c838c3f4b907
< 3.3.0
MEDIUM 4.4 The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
37aa3d05-79b6-49ea-b698-afa78615e438
< 1.2.9
MEDIUM 4.4 The Admin Bar & Dashboard Access Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set… wordfence
3786d672-f181-4d4d-9eb2-a86b70ff2794
< 2.2.14
MEDIUM 4.4 The Carousel Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to… wordfence
37342a62-97cd-43ef-af27-33092e840e67 MEDIUM 4.4 The Simple User Meta Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user meta value fi… wordfence
372149c4-b6b4-43c8-896f-af69712f3a82
< 2.6.96
MEDIUM 4.4 The Smart Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
36fd8125-f876-49c2-a0bb-4c7ef95b462c MEDIUM 4.4 The WP htpasswd plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7 … wordfence
36f37875-69fe-41cb-a68d-ad73d53d1a83
< 2.6.12
MEDIUM 4.4 The WP-Lister Lite for Amazon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al… wordfence
36d2d414-3798-441c-a5bc-4e0560499336
< 2.0.68
MEDIUM 4.4 The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all version… wordfence
36abd7e9-0ca4-4c22-ab13-08f2632a6797
< 3.0.5
MEDIUM 4.4 The Top Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, … wordfence
← Prev 1326 1327 1328 1329 1330 1331 1332 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top