🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1340 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1289ead7-1af1-417d-aa47-7d07268f956c
< 3.7.1
MEDIUM 4.4 The Popup Box plugin is for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_html’ parameter i… wordfence
12589b0a-5067-4368-a5a8-639cf381c0a6
< 3.2.0
MEDIUM 4.4 The Save as PDF Plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
12532f84-bc76-4968-a01f-f879ab41b901
< 3.1.4
MEDIUM 4.4 The Restrict Usernames Emails Characters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set… wordfence
120bc64f-05ec-41e7-9ed4-d88014f4a3ea
< 3.2.11
MEDIUM 4.4 The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
11e21460-ea79-4c19-82a9-388825985673 MEDIUM 4.4 The Link Shield plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
11dba817-b913-42b1-baa0-ec480674f858 MEDIUM 4.4 The My auctions allegro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
10f28404-acd0-40de-af42-2970b5b25bde
< 2.2.2
MEDIUM 4.4 The Aajoda Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version… wordfence
10ccb769-b186-41c4-b0e8-84b9c4d5e7b0
< 1.35.1
MEDIUM 4.4 The YITH WooCommerce Tab Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all v… wordfence
10c31c9c-ada9-43b5-a595-ca00b12d6840
< 4.12.4
MEDIUM 4.4 The Ajax Search Lite – Live Search & Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admi… wordfence
10c1b000-537a-4009-a740-19666505989e
< 3.7.12
MEDIUM 4.4 The Ultimate Dashboard – Custom WordPress Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
10aa1dd7-f909-4ebe-b29b-2f2743b3e08a
< 5.30.10
MEDIUM 4.4 The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm… wordfence
106a604f-0bff-444e-9d76-f6508bcc0cea
< 1.2.7
MEDIUM 4.4 The Elastic Email Sender plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
1063ecb4-a0a0-47d9-8629-f4f6a29bf5c9
< 2.1.6
MEDIUM 4.4 The Image and Video Lightbox, Image Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via numerous… wordfence
103a3e6e-8891-4a6f-a949-f8a5e19df8bf MEDIUM 4.4 The WeShare Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
0ffd695b-33e3-49b6-ad3a-98b2a645f827 MEDIUM 4.4 The Archives Calendar Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… wordfence
0ff001c2-95f9-42a2-b5a3-74937be41756
< 3.11
MEDIUM 4.4 The Menu Image, Icons made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
0fb82b48-3cf8-47a5-b68d-e37a1823a125 MEDIUM 4.4 The Auto Login New User After Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'al… wordfence
0fa5b6f2-94cc-47b8-986a-a3c525a7e777 MEDIUM 4.4 The URL Shortener by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… wordfence
0f93f3c4-555c-4fb5-b4ad-b03cdba82fb8
< 6.14.1
MEDIUM 4.4 The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for Wo… wordfence
0f8619e9-525d-425a-88c4-464cca570277 MEDIUM 4.4 The WP Cookie plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.0 … wordfence
0f83e62e-0a6f-4d95-93c4-552d59245552 MEDIUM 4.4 The WordPress HelpDesk & Support Ticket System Plugin – Octrace Support plugin for WordPress is vulnerable to Stored C… wordfence
0f5f8bd5-435a-4a53-8fa2-55674f39b78b
< 4.7.8
MEDIUM 4.4 The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via Language Settings in versions up to, and incl… wordfence
0f45583e-1438-47af-871c-efd59345c727 MEDIUM 4.4 The LotekMedia Popup Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in a… wordfence
0f3303db-9ba6-4638-ba96-151cf91db85b MEDIUM 4.4 The Complete Open Graph plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions… wordfence
0ea99921-5dda-42aa-99f8-43e52f3362c8 MEDIUM 4.4 The WP Cookie Law Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
← Prev 1337 1338 1339 1340 1341 1342 1343 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top