πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1338 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
18f0d0fd-3d1a-4e93-8e06-9cae7d64faf7
< 1.2.7
MEDIUM 4.4 The Plugin Notes Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
18d9c8f2-1d27-40de-8841-5fe21dcf620b MEDIUM 4.4 The Accessibility Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
18cbf346-91a3-4856-930e-7753eb1470d9
< 1.9.7
MEDIUM 4.4 The Best Chart Plugin – Chartify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
18c0ecc5-b3e2-4ac0-b901-dae397e2d57c MEDIUM 4.4 The Simple Popup Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions… wordfence
18a4fa4b-5c99-4347-8b34-e49f7e0972be
< 2.1.3
MEDIUM 4.4 The Keep Backup Daily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the backup title alias (`val… wordfence
1879fc8e-614b-4938-9274-e35de8db393f MEDIUM 4.4 The Pinterest Verify Meta Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
18643abb-171c-43d9-ad62-3414679eb402
< 4.6.1
MEDIUM 4.4 The Tournamatch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
18455e08-6593-4835-bd72-beb04bda2930
< 2.3.11
MEDIUM 4.4 The Responsive Gallery Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
1824b530-0e9f-43ec-ab79-8a1057e9c1e5
< 1.10.6
MEDIUM 4.4 The URL Shortify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1… wordfence
177f7111-b487-4e52-9106-54e0095a5dd4
< 1.22
MEDIUM 4.4 The underConstruction plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio… wordfence
175d4508-d638-4153-bd0d-30f0e50ba774 MEDIUM 4.4 The RDFa Breadcrumb plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
174b9b5a-82a3-4ee4-b926-edb27e38652a
< 1.3.1
MEDIUM 4.4 The Reading progressbar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.3.1 due to… wordfence
173661aa-6895-41d6-8869-6abfd2eadf31 MEDIUM 4.4 The Yandex Metrica Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in vers… wordfence
17093f18-09e2-425c-b1fc-60766234be49
< 4.9.18
MEDIUM 4.4 The Category Posts Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
16f183a6-b8db-461e-b17d-2faa528ff0ff
< 2.4.16
MEDIUM 4.4 The Booqable Rental Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booqable_company_n… wordfence
16e8e097-a332-4c8e-87fb-aabe5d00ae05
< 2.5.21
MEDIUM 4.4 The Kanban Boards for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
168e8512-d551-47f9-bc2b-c458180a6d13 MEDIUM 4.4 The External Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up … wordfence
167ae586-1f18-43ac-a7c1-e67a00ce8787 MEDIUM 4.4 The Tiny carousel horizontal slider plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set… wordfence
166e1d3a-3fd9-4ab0-ba0d-707c6d59e0cd
< 2.2.1
MEDIUM 4.4 The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
165bf4d4-0f97-4c51-bc55-ad14f3e4aae9 MEDIUM 4.4 The Gestion-Pymes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
1627ec2a-f91d-4ed7-acb8-a3fb63b45731 MEDIUM 4.4 The SpiderVPlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
161c2365-932f-44d0-a76c-4aeb01f9379c
< 1.8.5.2
MEDIUM 4.4 The Charitable plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.5… wordfence
16130c5d-9865-4953-b078-0b448722e36d
< 4.6.20
MEDIUM 4.4 The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Stored Cro… wordfence
159ddb06-e7c4-4279-a8a1-c78a02e15891
< 5.7.16
MEDIUM 4.4 The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin… wordfence
1597759b-48e3-4d7f-91d1-8f15f3cbdb62
< 2.2.9
MEDIUM 4.4 The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
← Prev 1335 1336 1337 1338 1339 1340 1341 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top