🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1331 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
31e11aff-056f-47c4-b5d1-c67af350585d
< 1.0.8
MEDIUM 4.4 The Fixed HTML Toolbar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
31cedfdf-5abc-4d51-b5b1-960159512c38 MEDIUM 4.4 The Varnish/Nginx Proxy Caching plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
318c7c3e-3872-4a90-92c6-d93ce2fd4333
< 3.0
MEDIUM 4.4 The Reservit Hotel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … wordfence
313906d3-3999-4255-b9ac-580d9d3e80e6 MEDIUM 4.4 The WP Social Meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … wordfence
310e2405-b6ff-4f52-9502-09fa7d5fcc62
< 2.2.3
MEDIUM 4.4 The Ocean Product Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
310b8622-8cc5-4fdb-8f83-b541aad136ee MEDIUM 4.4 The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
31064f51-3765-403d-b07d-dc2bb286b82d
< 2.4.0
MEDIUM 4.4 The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includ… wordfence
30f7560e-8713-4214-911a-18157c113d2a
< 3.1.32
MEDIUM 4.4 The Icegram Engage – Ultimate WP Popup Builder, Lead Generation, Optins, and CTA plugin for WordPress is vulnerable to… wordfence
30dbc840-e281-405c-82ed-7f92761db8ae
< 4.0.1
MEDIUM 4.4 The Save as PDF plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
30c34ea7-3df8-4ba8-bea8-4c785b23a4f4
< 2.5.11
MEDIUM 4.4 The Jobs for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
308f6887-7c1c-4efd-85e2-b71bb6d26dab
< 2.08
MEDIUM 4.4 The Sp*tify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settin… wordfence
30821418-48c0-4bc6-8bf1-f558671bff24 MEDIUM 4.4 The Responsive Header plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple plugin settings par… wordfence
3044dbfc-e12d-47e0-a297-67ff0510eded
< 2.3.15
MEDIUM 4.4 The Verified Reviews (Avis Vérifiés) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via admin s… wordfence
300c6ea4-4eed-4be5-abfd-ec4ad9b741d3
< 3.7.39
MEDIUM 4.4 WordPress Core, in versions up to 6.0.2, is vulnerable to Stored Cross-Site Scripting that can be exploited when malicio… wordfence
2ff7ab4f-bb00-4443-a06b-f61c53da9876
< 9.8.1
MEDIUM 4.4 The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via Button … wordfence
2ff5094a-8cf2-4c18-921d-7ec31d60c13a
< 4.1.6
MEDIUM 4.4 The KBucket: Your Curated Content in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
2fe11179-6e18-44ae-a5f9-334e334cff73
< 13.6
MEDIUM 4.4 The WP Google Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
2fc69243-2d28-4224-950e-c2ac36675f49
< 2.4.3
MEDIUM 4.4 The SAPO Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.2 … wordfence
2fb9dc9f-1ba5-4a2c-bead-3c3a6deb61b1 MEDIUM 4.4 The Get Your Number plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up … wordfence
2f8b8bfe-8d73-4289-b212-7baf7bceaaf6
< 4.4.5
MEDIUM 4.4 The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in version… wordfence
2f89bb45-2872-4081-a3b8-a1f11bbdbc55
< 1.2
MEDIUM 4.4 The Mhr Post Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Header Title value in all … wordfence
2f2ed813-3bf3-4ee3-a030-778cbd93bba3
< 1.8.10
MEDIUM 4.4 The Chat Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up… wordfence
2f032d32-9e7d-4510-b4ea-4b57c0b80977
< 6.1.81
MEDIUM 4.4 The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
2efbb0af-fda5-4c1b-a495-24fa7efc689e
< 1.0.10
MEDIUM 4.4 The Post Connector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up t… wordfence
2ed0fcbc-8cf7-4227-8f78-a10a2df83286 MEDIUM 4.4 The vipdrv plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.3 due… wordfence
← Prev 1328 1329 1330 1331 1332 1333 1334 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top