πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1335 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2290c2a0-2b13-4aee-9d04-0ea6ec20d81d MEDIUM 4.4 The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
2290b13e-a5c6-4ec7-86c0-f2cd2a880e8e
< 1.32.0
MEDIUM 4.4 The Hubbub Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
227cf3fe-4e76-4827-ac92-788bca450b52
< 2.06
MEDIUM 4.4 The WP Brutal AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to,… wordfence
2241fa07-b6b7-4e5d-8951-ae844a7b88e8 MEDIUM 4.4 The WP BaiDu Submit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up … wordfence
223d62cc-61ee-4818-9521-a772c1d57d59 MEDIUM 4.4 The twinklesmtp – Email Service Provider For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
222848a7-e079-4d56-9917-ec1d916efdcf MEDIUM 4.4 The WP-reCAPTCHA-bp plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
2210b056-49d4-4212-8e65-1215c71b7e9a MEDIUM 4.4 The Himalayas theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2 d… wordfence
220766ef-29a6-46f6-8c67-d1879db79400
< 1.8
MEDIUM 4.4 The wpShopGermany IT-RECHT KANZLEI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
21cd81aa-c3f2-4413-8a07-06c065f47569
< 3.4.18
MEDIUM 4.4 The Branda plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.17 du… wordfence
21cc5aec-ab5f-412b-aed0-bb41584a84cf
< 2.1
MEDIUM 4.4 The wpShopGermany - Protected Shops plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings… wordfence
21b4d1a1-55fe-4241-820c-203991d724c4
< 1.8.19
MEDIUM 4.4 The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in versions up … wordfence
21a3e3f1-9503-49f4-9b84-8b7c38c22e69
< 2.0.6
MEDIUM 4.4 The Themify Audio Dock plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
219f732e-abd8-463c-a43e-f92371356e3d MEDIUM 4.4 The Bot Block – Stop Spam Referrals in Google Analytics plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
219de193-32d0-40b0-a471-bf8bf6e2bb62
< 1.1.7
MEDIUM 4.4 The Cab fare calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vehicle title setting … wordfence
2181ede3-d8ac-4b62-98e5-7f4448a8cee4 MEDIUM 4.4 The Easy Logo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to… wordfence
21238925-b87c-43ea-b4ab-9b5d311d3a0a MEDIUM 4.4 The WP-Eggdrop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
211ffeb3-6f6b-4b90-b229-acdee49a801a
< 0.7.0
MEDIUM 4.4 The Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content plugin for WordPress … wordfence
210fd125-285d-4d07-bd39-b5ea222025ea
< 3.5.2
MEDIUM 4.4 The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se… wordfence
20e0e651-8330-4062-8fb4-f0545befcb1a
< 5.8013
MEDIUM 4.4 The Ebook Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Order Details in all versions … wordfence
20b3cd2a-ee32-49e0-8281-16afb8e42448
< 5.5.0
MEDIUM 4.4 The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … wordfence
20b11bbb-fd27-4c0c-9205-fd2164c39392
< 4.9.20
MEDIUM 4.4 The Category Posts Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
20a6a58f-b6c0-4132-932b-c6def8e9e7c0 MEDIUM 4.4 The gAppointments - Appointment booking addon for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
208c5ed1-879f-45ea-833e-d2e54c4f063f
< 9.0.33
MEDIUM 4.4 The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and incl… wordfence
20863474-01f7-45f7-b71f-b7ea920649ec
< 2.0.9
MEDIUM 4.4 The Legal Terms and Conditions Popup for User Login and WooCommerce Checkout – TPUL plugin for WordPress is vulnerable… wordfence
2083fdf7-e251-4162-b38f-8dab4395a8a7
< 0.9.34
MEDIUM 4.4 The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al… wordfence
← Prev 1332 1333 1334 1335 1336 1337 1338 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top