πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1339 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
158e5a3f-32f4-40b8-840e-2c70a9485b1a
< 2.1.2
MEDIUM 4.4 The What Would Seth Godin Do plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… wordfence
158a63c1-1b2e-4fbf-ac86-43471ba8ebc2 MEDIUM 4.4 The GDPR Cookie Consent by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… wordfence
152384a2-69e0-41be-b02a-634fca714f4b
< 1.0.7
MEDIUM 4.4 The Elementor Element Condition plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all ve… wordfence
1516ebe7-4d16-4e97-9baa-bc5857f95126 MEDIUM 4.4 The Buzz Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom Buzz Avatar' (buzz_c… wordfence
1512dcea-11b5-4176-973b-aa3fc088865b
< 5.5.10
MEDIUM 4.4 The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin… wordfence
14d41282-740d-4602-b869-c2b313c96fbc MEDIUM 4.4 The FM Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
14c94d47-c911-4874-a897-58f4c0800329
< 2.3
MEDIUM 4.4 The Userlike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and… wordfence
14baad86-ef7d-4d9c-b878-ea97f66b37a0 MEDIUM 4.4 The Tabs Responsive – With WooCommerce Product Tabs Extension plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
14ae1f7a-be81-4f4f-8cea-7afb824186aa
< 2.0.9
MEDIUM 4.4 The Meks Easy Ads Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
1496ce98-ee19-4f37-9ec7-eb0fafb5df19 MEDIUM 4.4 The Add to Feedly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to… wordfence
145fec62-87a7-4641-9ce4-dca5afb47d69
< 2.1
MEDIUM 4.4 The Add to home screen WP Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters inclu… wordfence
14014260-e872-48d8-8788-f89dbeec2080 MEDIUM 4.4 The AMP Enhancer – Compatibility Layer for Official AMP Plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
13fd7509-6d61-4eb0-9f85-cc40e074b819
< 3.0
MEDIUM 4.4 The Autocomplete Location field Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm… wordfence
13d544ae-fbca-42d9-9d74-5e018092e097
< 1.6.7.55
MEDIUM 4.4 The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to S… wordfence
136616d7-e6f3-4964-abc4-527074122c78
< 4.2.1
MEDIUM 4.4 The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al… wordfence
133e2834-ed47-4e76-b353-0de028657a6e
< 3.10.1
MEDIUM 4.4 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
13389191-cbda-4c39-8598-7c2b41f31da7
< 2.5.3
MEDIUM 4.4 The Simple Image Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
13344366-feb0-4987-9543-222e3d35dab3 MEDIUM 4.4 The Custom Dash plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
13209280-5822-492b-94fa-780ce6d38924 MEDIUM 4.4 The Dima Take Action plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
131a6a35-e0d2-4613-8614-24bf11011098 MEDIUM 4.4 The Viet contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
131614fa-fcaa-4105-b3ce-9926a413dd42
< 3.0.3.1
MEDIUM 4.4 The Everest Forms – Build Contact Forms, Surveys, Polls, Quizzes, Newsletter & Application Forms, and Many More with E… wordfence
13159a71-c183-4fc2-98af-8b9e60508a1c
< 2.1.9
MEDIUM 4.4 The Doofinder WP & WooCommerce Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settin… wordfence
12dc6952-d7a8-46da-ba7b-e8816c9c7cbf
< 3.10.5
MEDIUM 4.4 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admi… wordfence
12b4e363-248f-469a-a958-0b1ec5c6e37f
< 1.7.30
MEDIUM 4.4 The 360 Javascript Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜ref’ parameter … wordfence
128d45ec-941c-414c-b341-9964dc748132
< 10.6.1
MEDIUM 4.4 The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers… wordfence
← Prev 1336 1337 1338 1339 1340 1341 1342 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top