🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1341 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0e81b6c1-5af5-4ad4-92db-9dba76399857
< 3.6.5
MEDIUM 4.4 The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
0e1915d9-8ea9-4ab2-9746-3c49bc0bd7c8
< 4.23.3
MEDIUM 4.4 The Wordpress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute in … wordfence
0e170f98-692b-48f1-92b0-530cbe21440b
< 1.6.7.55
MEDIUM 4.4 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to S… wordfence
0df152a1-908c-4ef7-bf48-69c05b13fced
< 5.1.6
MEDIUM 4.4 The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
0dca168f-a383-42fc-91ba-d78a5d7e6724
< 1.26.7
MEDIUM 4.4 The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se… wordfence
0dbacaae-1d41-4d29-b477-e624822e287d MEDIUM 4.4 The Sticky Social Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
0d5d4571-f6a1-4994-9763-84578b65941c
< 4.0.9
MEDIUM 4.4 The Social Media Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "VK URL" field in all … wordfence
0d10f5cd-d449-46f1-a347-f45a1db65999
< 4.0.3
MEDIUM 4.4 The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘snippet_content’ parame… wordfence
0cbc3828-7fdc-4128-bd6e-79911756eae4
< 1.1.4
MEDIUM 4.4 The Timeline Module for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via title tags … wordfence
0cb8bd81-72a4-4b53-850b-78cc5e05043f
< 1.4.5
MEDIUM 4.4 The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions … wordfence
0cb48233-0885-4634-9298-b42c45219ee6
< 1.15.7
MEDIUM 4.4 The 3D FlipBook – PDF Flipbook WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via setting… wordfence
0c976e5a-2f6c-4632-99a7-a512b3dd38e6
< 0.1.18
MEDIUM 4.4 The WP MultiTasking – WP Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpmt_m… wordfence
0c7497fc-e42c-49a6-99ee-6ec774cc4617
< 1.1.4
MEDIUM 4.4 The Smart App Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
0c347b9f-d297-4cb5-9c4a-1001d845ed5a
< 2.5.3
MEDIUM 4.4 The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… wordfence
0c30cfa6-dee2-40d2-b5ac-06451e9218fb
< 2.4.4
MEDIUM 4.4 The IP Based Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
0c23cc3c-3c76-4ba8-8fa6-6ed0507a35c9 MEDIUM 4.4 The "Amazon affiliate lite Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
0c20f87e-3670-444c-aa8a-28988dfe2fd9
< 3.5.8
MEDIUM 4.4 The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in… wordfence
0b768777-d502-47b4-bf78-03c4cd525063
< 1.0.7
MEDIUM 4.4 The WP MyLinks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and… wordfence
0b270ec6-8dc1-432b-bf68-671966a9761a
< 4.3.1
MEDIUM 4.4 The SULly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, an… wordfence
0acb365c-b5f2-4377-875b-69278a8ff96e
< 1.27
MEDIUM 4.4 The Ona theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.26 via … wordfence
0ab546cc-b099-4d26-bf42-785952fcfd8c
< 2.6.6
MEDIUM 4.4 The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' … wordfence
0aac81b0-8d40-4c16-99b0-558ad7132698
< 1.4.7
MEDIUM 4.4 The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
0a79f8f6-a708-4db1-806d-1f782bbcfd16
< 4.2.7.5.1
MEDIUM 4.4 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin sett… wordfence
0a70063e-b2d5-44a3-9a6f-3bbc9f4a0ff3
< 2.0.1
MEDIUM 4.4 The Easy PayPal Buy Now Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
0a4c33bd-1394-4015-812b-dfcee5cf829a MEDIUM 4.4 The Pop Up plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.1 due t… wordfence
← Prev 1338 1339 1340 1341 1342 1343 1344 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top