ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1343 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
073db945-becb-4b81-a1f9-7b73c30a8c50 MEDIUM 4.4 The AM Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.13.1… wordfence
07372843-f7d3-4ae4-96b4-ef3f475504ff
< 2.1.15
MEDIUM 4.4 The Yatra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'activity_image_id' and 'destination… wordfence
07357de3-bbf5-40d3-a171-3b624b572e6c
< 0.5.6.2
MEDIUM 4.4 The Advanced Post List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
071b5c32-b6ac-402a-af74-6ecd05279d93 MEDIUM 4.4 The Kanban Boards for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
07043be9-c81e-4021-90af-976ae57c0bec MEDIUM 4.4 The qnotsquiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qnotsquiz_custom_start_text' pa… wordfence
06c86c87-840c-4ca6-9582-98254194eb1b MEDIUM 4.4 The Vertical Marquee Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the admin settings in … wordfence
06c76b28-3a0a-4070-be37-1aa5908eb888
< 1.3.3
MEDIUM 4.4 The Include Me plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2… wordfence
06a29065-8e20-4ead-865f-addd84917336 MEDIUM 4.4 The Append extensions on Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
06503fb4-1891-4279-bce9-9667d00f69e1
< 3.3.9.3
MEDIUM 4.4 The WordPress WP-Advanced-Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… wordfence
063a245d-bd9e-49ac-bdf0-549a25eba9fe MEDIUM 4.4 The FitVids for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
06294c35-6d58-4270-b143-757831fc5da6
< 1.8.2
MEDIUM 4.4 The Campaign URL Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple form fields with… wordfence
0616a69a-20a5-476c-904a-881b31b9da18 MEDIUM 4.4 The Logo Slider , Logo Carousel , Logo showcase , Client Logo plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
05f5addb-ab1d-4b67-b969-3b95d43be790
< 3.0
MEDIUM 4.4 The wSecure Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to,… wordfence
05b3c8de-6802-4eb2-855c-b13a9005963f
< 1.5.3
MEDIUM 4.4 The CM On Demand Search And Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
05aa6132-7591-4d2a-a44b-7d57a24ca8d8 MEDIUM 4.4 The cookieBAR plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.0 … wordfence
059e262b-ee63-4f8b-82ab-c12bcf70f879
< 7.3.1
MEDIUM 4.4 The Optima Express + MarketBoost IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin … wordfence
059d3ba9-8530-4977-b59a-f1c2976641d7
< 2.93
MEDIUM 4.4 The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
0587bf5f-96cf-4a59-9209-6b559a013517
< 1.7.36
MEDIUM 4.4 The Login with phone number plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
0584611c-39eb-4ed9-9e2b-aa04013f8f74
< 1.1.6
MEDIUM 4.4 The WP Google Street View plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
05614ee6-ce14-44fe-a819-8f116563dbdd
< 1.0.74
MEDIUM 4.4 The EZP Coming Soon Page Plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
055cc26b-1e24-4e39-89c8-bdc4a69ce938
< 4.4
MEDIUM 4.4 The Rocket Maintenance Mode & Coming Soon Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm… wordfence
052be7d6-bc76-4af9-bf65-2494a46156fc MEDIUM 4.4 The Landing pages and Domain aliases for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
05206a31-033e-49b9-9b66-5a6165782643
< 2309
MEDIUM 4.4 The Table of Contents Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versi… wordfence
0516aa04-ff94-4da4-80b7-ea351d11a288 MEDIUM 4.4 The Admin Menu Post List plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
04df6505-46c1-4e66-a363-4ccebacb5e42
< 1.2
MEDIUM 4.4 The Call Now Accessibility Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i… wordfence
← Prev 1340 1341 1342 1343 1344 1345 1346 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top