πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1334 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
261b21b7-6bed-4df9-bbb6-f395c0fd4f22 MEDIUM 4.4 The Simple Link List Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
25cfa88b-5b13-43d9-823b-c5d2064f5888 MEDIUM 4.4 The Contact Info Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
25c35a42-9f1a-4f67-a074-c6359e8b1a41
< 4.1.7
MEDIUM 4.4 The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
25a566ed-9ed6-4c72-9728-49a0edfb5ba5
< 1.1.0
MEDIUM 4.4 The Auto Rename Media On Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
25a55dc6-6bfe-40dc-afae-e91670f6b73c
< 1.07.7
MEDIUM 4.4 The Advance Portfolio Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
257eb4c5-ca32-42ac-9f04-21adddcc96f0 MEDIUM 4.4 The Popup4Phone plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
2567ecc4-1346-4092-8c99-ffa5064e6a3f
< 4.2.18
MEDIUM 4.4 The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se… wordfence
251b17a7-781f-4f17-af90-9a6fbae69243
< 2.0.7
MEDIUM 4.4 The Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site plugin for WordPress is vulnerable to… wordfence
25018b54-9938-4261-80fb-d0c59d7fe456
< 5.1.8.9
MEDIUM 4.4 The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1… wordfence
24fc2554-375a-4216-91bf-41921cc4b436
< 1.0.9
MEDIUM 4.4 The WP Roadmap – Product Feedback Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se… wordfence
24226595-6ae7-44c2-a159-5b69808273fa
< 1.5.4
MEDIUM 4.4 The Product Labels For Woocommerce (Sale Badges) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
24184443-9737-4117-89cf-02cf1e2a07f2
< 0.7.3
MEDIUM 4.4 The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
23fc3221-73b0-4407-a5d7-f145c3dbc1e6
< 1.8.9
MEDIUM 4.4 The File Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
23f7f4ad-f9d5-44b7-8354-5145b003fd20 MEDIUM 4.4 The WordPress Custom Settings plugin is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … wordfence
23ad80bd-3e35-4610-b917-7242a4292adf
< 5.2.8
MEDIUM 4.4 The Generate Images – Magic Post Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin… wordfence
23a2b1ac-2183-48ae-8376-fb950fe83fd9 MEDIUM 4.4 The Custom Post Type Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings… wordfence
2363b377-b74e-43ad-969f-6bce0bac6000
< 1.23
MEDIUM 4.4 The Add Code To Head plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
234c8c32-0661-4f54-ab16-c630d9aae82e MEDIUM 4.4 The SensorPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 … wordfence
23447ee8-e852-4ddf-a333-5d0df01c4195
< 1.5.2
MEDIUM 4.4 The Smart Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
23334d94-e5b8-4c88-8765-02ad19e17248
< 4.19.2
MEDIUM 4.4 The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Script… wordfence
233319cc-10fc-4a15-be35-df772e700639
< 3.6.9
MEDIUM 4.4 The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vuln… wordfence
232378ba-5992-4ac0-975b-8c329bce83b6
< 3.2.7.1
MEDIUM 4.4 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin… wordfence
22ff0b0c-ffd9-4aae-9e49-069fd1b47f17
< 3.8.7
MEDIUM 4.4 The Popup Box – Best WordPress Popup Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admi… wordfence
22bc7a0c-8a89-461b-8838-788dd6d5c63b
< 1.5.49
MEDIUM 4.4 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros… wordfence
22a32bb6-fe22-4c5e-91f6-de3c38d7d19e MEDIUM 4.4 The Viet Nam Affiliate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
← Prev 1331 1332 1333 1334 1335 1336 1337 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top