🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1337 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1cc50245-365a-419d-a85c-fbd658d004ae
< 4.7.8
MEDIUM 4.4 The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions up to, and includ… wordfence
1c4fd888-aeaf-4451-a151-8f884bc22f0b MEDIUM 4.4 The LinkedIn SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'linkedin_sc_date_format', 'li… wordfence
1c441ceb-0363-4117-afd6-afa253343cbe MEDIUM 4.4 The Free Quotation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … wordfence
1c36c69c-dc6c-436c-95c1-a0f7fe526fa6 MEDIUM 4.4 The WP-FB-AutoConnect plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
1c33c193-618d-4e36-bb36-350cac6e2948
< 1.15.33
MEDIUM 4.4 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Store… wordfence
1c1ca3cc-544a-4d75-aaf3-e26e2fc5ce5a MEDIUM 4.4 The E-namad & Shamed Logo Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
1c02e03a-7f96-4efa-9071-4a76fb21900d
< 3.5.2
MEDIUM 4.4 The Fast Velocity Minify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver… wordfence
1b70b9b1-bde9-4a32-ae7b-a4c8d73abbc4
< 3.0.4.2
MEDIUM 4.4 The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio… wordfence
1b645d0e-daee-4926-af47-05cacf811fbf
< 1.6.6
MEDIUM 4.4 The Review Stream plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
1b5a6633-4ce3-4249-a5b0-d8f960aae903
< 1.100.0
MEDIUM 4.4 The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s… wordfence
1a850176-973c-49aa-a420-e379223b6dc3
< 1.2.7
MEDIUM 4.4 The SEO By 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to,… wordfence
1a5b5b9d-9549-4931-8b27-c8a0d5bcf53c
< 1.4.4
MEDIUM 4.4 The FunnelCockpit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
1a507489-f337-4b47-9506-daea1b426798
< 5.7.26.4
MEDIUM 4.4 The Quick Paypal Payments for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up t… wordfence
1a374d8a-3754-4228-95ed-dc0ba1df40da
< 2.2.4
MEDIUM 4.4 The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers… wordfence
1a331934-3bf2-4406-bc45-a897a3da5d90
< 1.3.53
MEDIUM 4.4 The Contact Form Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
1a2002fd-7fe4-4cc1-8b74-096a0db09247
< 3.1.15
MEDIUM 4.4 The VForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.14 due… wordfence
1a0f671d-d596-4225-bffd-57776224dd0e
< 4.5
MEDIUM 4.4 The Advanced Excerpt plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
1a0ba31d-d2d8-4614-8f77-a041c25c0519
< 2.0.0
MEDIUM 4.4 The SMTP Mailing Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via mailing settings in version… wordfence
19d15d0e-40be-434d-a4c9-d835d4f81230
< 4.7.1
MEDIUM 4.4 The Ultimate Client Dash plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
19c9cf3e-553b-4cbd-9f2c-803e188a2581
< 1.4.4
MEDIUM 4.4 The UniConsent Cookie Consent CMP for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
19a70aa0-7075-4922-8feb-25b7fbe9da42
< 1.1
MEDIUM 4.4 The Auto Location for WP Job Manager via Google plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad… wordfence
19a5a9f3-637c-42af-9775-5651a14cf516
< 3.4
MEDIUM 4.4 The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpfront-notifi… wordfence
19737921-5d5e-4a1a-82f7-e771cccfff49 MEDIUM 4.4 The Pending Order Bot plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
195ac5fe-11e9-4ae4-b9ef-2bf1692789a9
< 1.5.1
MEDIUM 4.4 The VikRestaurants Table Reservations and Take-Away plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
1907308f-a722-48ce-8da4-a6c21ee29575 MEDIUM 4.4 The Quick Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
← Prev 1334 1335 1336 1337 1338 1339 1340 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top