πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1342 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0a30d35c-9883-4b0f-83a2-494401c45d8e
< 5.1.20
MEDIUM 4.4 The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner… wordfence
0a158653-f80c-48a3-840e-20ee7e85925a
< 3.1.2
MEDIUM 4.4 The Floating Chat Widget - Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… wordfence
0a0ced4d-368d-4f12-9099-1f8c0b0fe245
< 1.3.1
MEDIUM 4.4 The 123.chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, an… wordfence
09e20941-ee86-46a0-8b79-e7cd703c61af
< 3.10.0
MEDIUM 4.4 The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
09bef3c5-991d-4eb1-b613-0b7d45ab5329 MEDIUM 4.4 The HL Twitter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
09ac7546-0572-4446-99f7-fe84f76fac9b
< 1.8.8
MEDIUM 4.4 The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.7 … wordfence
098efef9-f5e0-4827-bd4e-88867b7dc3b7
< 7.3
MEDIUM 4.4 The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… wordfence
09814382-476b-4686-b3e8-d80aade92b1f
< 4.9.17
MEDIUM 4.4 The Category Posts Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the excerpt_more_text fi… wordfence
097f6887-e15f-4e35-ab12-1115630e13cc
< 5.78
MEDIUM 4.4 The Ebook Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions before … wordfence
097c3257-6479-4169-ac17-cb1629aef7a1
< 9.1.8
MEDIUM 4.4 The Nex-Forms Express WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
095c6359-112d-4abc-a69b-a623dfd103c0
< 1.1.0
MEDIUM 4.4 The Emplibot – AI Content Writer with Keyword Research, Infographics, and Linking | SEO Optimized | Fully Automated pl… wordfence
0926bcf2-9cce-420d-a02f-52675224a71b MEDIUM 4.4 The Easy Forms for Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… wordfence
0925fb98-2233-4f4b-8e70-c52d0b5086f1 MEDIUM 4.4 The WP Advanced PDF plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
08fec79c-888d-40e0-8e5f-6981658b67a8 MEDIUM 4.4 The Pondol BBS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.8… wordfence
087034aa-efd0-44b9-9a2f-3a625806bcaa
< 0.9
MEDIUM 4.4 The bodi0`s Easy cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cache-folder' paramete… wordfence
0868b6ba-3b73-4b8a-a8b4-3cea8771ba33 MEDIUM 4.4 The EasyEvent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to… wordfence
08622a0a-2182-440b-a909-4ca6538f5008 MEDIUM 4.4 The Job Colors for WP Job Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
08593415-bbc9-4159-b5d5-84e4dde6c2c9
< 1.3.27
MEDIUM 4.4 The Open User Map | Everybody can add locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad… wordfence
08021121-94a1-4569-b8ab-417eec2be993 MEDIUM 4.4 The Backup Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions… wordfence
07e013b5-40e1-4187-951f-ee3b02371727
< 3.8.0
MEDIUM 4.4 The Inline Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver… wordfence
07c3c8d9-64c9-4d16-9a35-8477b358123f
< 2.5
MEDIUM 4.4 The CRM Memberships plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in version… wordfence
07b075a6-2339-4562-a096-0a46b58f1e9f
< 2.1
MEDIUM 4.4 The IP Vault – WP Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
078e110d-2e57-4bcf-b3fb-a4bbf70ea362
< 1.4.14
MEDIUM 4.4 The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin… wordfence
077f3152-9735-41c7-9a17-5202b3ee3152 MEDIUM 4.4 The Paytm Payment Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
076d1b28-bc43-4e70-995c-71b236e7f698 MEDIUM 4.4 The Kodex Posts likes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
← Prev 1339 1340 1341 1342 1343 1344 1345 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top