🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1333 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2a78b274-f83f-4168-a8d2-9ee945518b60
< 1.0.4
MEDIUM 4.4 The WP Food Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up … wordfence
2a6dfdec-c1c6-4300-ab0a-9fd1c550d09f
< 5.1.4
MEDIUM 4.4 The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all version… wordfence
2a5c6b05-6e28-40be-80cb-9f95241a4fc6
< 1.47
MEDIUM 4.4 The We’re Open! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to… wordfence
2a42a360-9b85-4179-ba75-4eab06026b51
< 4.7.1
MEDIUM 4.4 The BEAF plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.0 due t… wordfence
2a427b26-4a0d-4351-8a8b-ec5da1345ebd MEDIUM 4.4 The Persian Fonts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
298af603-43fc-4fde-83b5-ac36f1b35bca MEDIUM 4.4 The Newsletter Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
29652f77-032c-4637-9dbf-cfd26b56ff19 MEDIUM 4.4 The Video Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
294de862-716c-4e17-a1cf-cade53207013
< 3.0.10
MEDIUM 4.4 The Klaviyo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and … wordfence
28f454e8-d0ce-4ad2-bcad-5011f75ec862
< 1.6.8
MEDIUM 4.4 The Review Stream plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
28cddb4c-32a1-4ea9-936d-5ec7ffd84753 MEDIUM 4.4 The SAHU TikTok Pixel for E-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… wordfence
288559f0-eab6-4933-a026-8413476af6eb
< 5.2.6
MEDIUM 4.4 The Ultimate Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ver… wordfence
287d8e07-35f5-4df6-a764-529860453660
< 1.9.1
MEDIUM 4.4 The Progress Planner plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
286df83a-d723-4443-b265-f91cf5abb385
< 1.38.3
MEDIUM 4.4 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored C… wordfence
2857e6c1-f6c4-46fb-9837-a6a6f5e48369
< 2.2.10
MEDIUM 4.4 The Carousel Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via slide options settings in all … wordfence
28509874-1544-41a6-b536-76db130816b7 MEDIUM 4.4 The Popping Sidebars and Widgets Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
280871a2-f09f-4cd1-93f1-c804cda6b4e7
< 3.2
MEDIUM 4.4 The MWW Disclaimer Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
277eb517-c949-41e9-becf-af056fd32f35
< 2.4.1
MEDIUM 4.4 The WP Original Media Path plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in … wordfence
27384009-2ce4-4644-90b2-5f252a1cf2a5 MEDIUM 4.4 The Google+ Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
272746cd-0817-4dcb-8a4c-f1d84ed960b2
< 2.2.17
MEDIUM 4.4 The EventON plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, … wordfence
26fc1484-3435-4467-a74c-6ba5736be450
< 1.2.62
MEDIUM 4.4 The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wi… wordfence
26decafa-2329-406a-a48b-f4e6867f60df
< 2.12.2
MEDIUM 4.4 The FormFlow: WhatsApp & Social Form Builder for Leads plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
26d12c52-d08f-4a6c-ba59-0e26dfb33ae5 MEDIUM 4.4 The Zweb Social Mobile – Ứng Dụng Nút Gọi Mobile plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
26c63d73-6ce2-4b3a-b0d9-29f7d9b368d5 MEDIUM 4.4 The Editorial Rating – Product Review & Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
26b7438e-438b-41eb-9458-2fba8ab1964d
< 3.3.9
MEDIUM 4.4 The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings… wordfence
2656c2f8-802d-4626-bf79-a14d80bf79bf
< 2.1.2
MEDIUM 4.4 The PopupAlly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to… wordfence
← Prev 1330 1331 1332 1333 1334 1335 1336 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top