🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1330 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3673a86c-1e11-45ad-8944-84a38aad53dd
< 8.53
MEDIUM 4.4 The IdeaPush plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,… wordfence
3663b35d-13ac-4d65-80bd-5800ed74f759
< 1.3.26
MEDIUM 4.4 The Product page shipping calculator for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
364f5b87-76c7-421e-80b9-ee0ee0241d17
< 1.0.82
MEDIUM 4.4 The CP Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.81 … wordfence
361deac0-f675-432c-b7d2-b99f168d476d
< 3.1.3
MEDIUM 4.4 The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty p… wordfence
36123fad-448e-4fdb-a076-5280b53d9671
< 1.3.5
MEDIUM 4.4 The Navigation menu as Dropdown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti… wordfence
35e0a997-190e-457a-b80c-7b4ecec97095
< 1.3.7
MEDIUM 4.4 The Optin Forms – Simple List Building Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
35c5b1cd-053c-4e1d-994f-003b89d5ff62
< 4.2
MEDIUM 4.4 The List Custom Taxonomy Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
35b1853f-0c19-4fc8-8878-9e8a9330f76a
< 2.8.45
MEDIUM 4.4 The Email Newsletter, Marketing, Email Automation and CRM Plugin for WordPress by FluentCRM plugin for WordPress is vuln… wordfence
3598445c-1d65-4e84-8db0-717aed66088b MEDIUM 4.4 The Beauty Contact Popup Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
35800696-19b3-4479-a961-5d05aeeb44bb
< 2.0.66
MEDIUM 4.4 The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
355decb2-2667-4056-836c-9ac8897f340e
< 11.19
MEDIUM 4.4 The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
35508e64-33a7-4d70-acaa-e9fae6920d95
< 4.4.11
MEDIUM 4.4 The Image Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
352e27ad-4266-4384-be2b-d94d241373a8
< 33.0.9
MEDIUM 4.4 The PPOM for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
3522b693-4719-4320-b921-78b9ef682a21
< 1.0.5
MEDIUM 4.4 The kontur Admin Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
34a8980a-92d6-485b-877c-8339a1cd5fe8
< 1.1.1
MEDIUM 4.4 The Simple Matomo Tracking Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
338edb1d-101a-4b6e-ac25-b59bd3e17f8b
< 2.9.4
MEDIUM 4.4 The NotificationX – Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floati… wordfence
33770bfd-c481-4e18-838b-89a5fb5b15f0 MEDIUM 4.4 The eBecas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in versions up to, and … wordfence
33210104-68fc-4d88-b681-b30e7abd6e18
< 1.0.12
MEDIUM 4.4 The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… wordfence
32f2fc21-165c-483f-ab81-48d8f221e4be
< 5.5.1
MEDIUM 4.4 The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … wordfence
32d3974e-8a45-48a4-869a-33b886c095e1
< 3.4.1.0
MEDIUM 4.4 The Nota Fiscal Eletrônica WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
3256da87-0d37-4c8f-9bac-95e3017e35d5
< 1.2
MEDIUM 4.4 The NinjaTeam Header Footer Custom Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin sett… wordfence
324fd823-8ec9-4187-8694-6160bad8e093 MEDIUM 4.4 The Real Post Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in a… wordfence
321b2b0d-8169-4e80-b86f-2ae29d9b8b7d
< 2.7
MEDIUM 4.4 The Basic Interactive World Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
320f4260-20c2-4f27-91ba-d2488b417f62
< 0.9.90
MEDIUM 4.4 The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ima… wordfence
31f3ad99-92fe-4c56-83e1-c4f777baa730
< 3.2.9
MEDIUM 4.4 The Nested Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, a… wordfence
← Prev 1327 1328 1329 1330 1331 1332 1333 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top