🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1332 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2ec96107-ae41-4886-8a46-5a2d6dd62aae MEDIUM 4.4 The Font Farsi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
2eb3b568-8689-4184-8091-0b84aa6b472d MEDIUM 4.4 The Timely Booking Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio… wordfence
2eb2adf2-127a-48cc-8908-8413f81ccf14 MEDIUM 4.4 The Show All Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
2ea71d63-27ce-4f24-b3ef-de38e6f25e0d
< 1.3.11
MEDIUM 4.4 The VigilanTor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vitor_realtime_timeout' admin… wordfence
2e82081e-17de-4394-9e46-0541090fbd7f MEDIUM 4.4 The Top Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
2e6fe647-d243-43ba-b619-d181560cb230
< 2.2.8
MEDIUM 4.4 The All-in-one Like Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
2e3358a9-3e73-4ee5-9426-8d8fc01739fe
< 1.1.8
MEDIUM 4.4 The Integration for Contact Form 7 and Constant Contact plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
2de90107-1a7e-4899-ae1e-cb9eeadfe64d MEDIUM 4.4 The CSSable Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio… wordfence
2ddc39a8-57b7-46be-878a-2e1cf3271bd2
< 1.0.21
MEDIUM 4.4 The Post Sliders & Post Grids plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al… wordfence
2d720466-e470-46a3-8129-3e58e1928f0d MEDIUM 4.4 The SimplyConvert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'simplyconvert_hash' option … wordfence
2d3863ec-0cc7-4128-a19e-fc1e2c31195e
< 1.3.4
MEDIUM 4.4 The Page Keys plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page_key’ parameter in all … wordfence
2d34c665-e99c-408e-b7ab-d08a1a51c6c4 MEDIUM 4.4 The WP Jump Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to,… wordfence
2c925848-1ba7-4009-93c2-1648dbf808e9
< 1.5
MEDIUM 4.4 The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title paramet… wordfence
2c8a487c-6bd5-480a-9945-ba465b38243f MEDIUM 4.4 The Pocket News Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings such as "… wordfence
2c7a1cb4-a61e-41ac-8ce2-06de5104a368 MEDIUM 4.4 The Bang tinh vay plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
2c78ab13-22ed-4f00-b132-c9ff99c51273 MEDIUM 4.4 The Contact Us Simple Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
2c230688-1524-4e3a-918b-34dbcc04330f MEDIUM 4.4 The Social Intents plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
2ba73538-fa6b-43d2-8253-759ee962c838
< 2.8
MEDIUM 4.4 The Wetterwarner plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7… wordfence
2b90c0a2-19b2-4846-9f62-2b02d28cc13b
< 5.1.8
MEDIUM 4.4 The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… wordfence
2b75dce8-3e31-45e8-b193-5df3e4391e56
< 1.5.2
MEDIUM 4.4 The Announce from the Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
2b696e0b-d4e1-4a81-9204-929100ade073 MEDIUM 4.4 The Eonet Manual User Approve plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings … wordfence
2b49897d-ebf5-4ac3-99c0-fa5e90818673 MEDIUM 4.4 The Emmet plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.3.4 due … wordfence
2b2714f7-9877-4d3d-a692-70fbf8584728 MEDIUM 4.4 The GuruWalk Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in ver… wordfence
2afbc0a4-32ad-4fc4-9b10-5c06784f72f3
< 7.0.6
MEDIUM 4.4 The WP Full Stripe Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
2ab86a42-2a8f-4cbc-a754-a3e307b1b73f
< 8.2.7
MEDIUM 4.4 The Website LLMs.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
← Prev 1329 1330 1331 1332 1333 1334 1335 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top