🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1344 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
04d7a97c-c2f8-4c9e-b913-343c8e3dec26
< 3.6.5
MEDIUM 4.4 The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
046ecbe5-4b2f-40d3-8585-4d4230ba33f0 MEDIUM 4.4 The Dave's WordPress Live Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… wordfence
0459a6bd-334d-43b7-b289-271108564a53
< 3.3.3
MEDIUM 4.4 The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for Word… wordfence
04597908-7086-4158-ae2b-8aa634a217c6
< 7.6
MEDIUM 4.4 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
044e110d-2435-41b8-8aec-917c329b944c
< 1.3.1
MEDIUM 4.4 The Formilla Chat and Marketing Automation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Fo… wordfence
04434abc-963f-40b7-8ed6-29bd39cf64b9
< 1.7.2
MEDIUM 4.4 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se… wordfence
0417e2d7-0c0a-48e1-bf18-3f5e16b1b8a0 MEDIUM 4.4 The AnnounceKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
03faf5af-6123-4db3-828f-88861f8116de
< 3.8.6
MEDIUM 4.4 The Ultimate Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.8.6 due to … wordfence
03ad3677-1b02-4f22-af50-e88b2ec83f54
< 3.2.13
MEDIUM 4.4 The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textarea.descri… wordfence
037b5c2c-510a-4fa5-b489-cb0478603be2 MEDIUM 4.4 The WMF Mobile Redirector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in a… wordfence
035d9433-08db-4849-aae3-735be9f82f52 MEDIUM 4.4 The GigPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,… wordfence
0348d465-f351-4c52-b293-8b3b058292b9
< 5.1.7
MEDIUM 4.4 The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vu… wordfence
033f8b21-6c5a-433f-b60d-5509fb203234
< 1.2.27
MEDIUM 4.4 The Email Subscription Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
0332e106-1f97-4c52-b084-ea15d31dee72
< 2.2.44
MEDIUM 4.4 The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_setti… wordfence
03073726-58d0-45b3-b7a6-7d12dbede919
< 1.5.4
MEDIUM 4.4 The Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline) plugin for WordPress is vulnerabl… wordfence
02e63068-02a8-4106-b64e-430c24815e55
< 1.19.5
MEDIUM 4.4 The HTTP Headers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
02ddfc75-8a9e-4a8e-8339-52348a963c69 MEDIUM 4.4 The KP Fastest Tawk.to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
02b5aefe-ba27-4273-927c-7779df83eb18
< 11.21
MEDIUM 4.4 The WPMobile.App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $_POST['wpappninja']['app']['… wordfence
02930a65-91b6-475e-9673-063ba5929b6c
< 3.59.4
MEDIUM 4.4 The NextGEN Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
02402620-89db-448d-9028-379856735a2a
< 2.0.8
MEDIUM 4.4 The Woocommerce Vietnam Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $currency var… wordfence
022ab125-d086-40bf-aafb-65059b3c455f
< 1.26.3
MEDIUM 4.4 The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin … wordfence
01e21584-949b-4d2b-b0e8-2f4abe8416b2 MEDIUM 4.4 The Tooltip CK plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
01da1829-e3f4-4246-ae3d-72377c4b232e
< 1.0.19
MEDIUM 4.4 The Easy Testimonial Slider and Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in v… wordfence
01d9b7c1-8f34-4c87-af68-a5e6c698b2d8
< 1.3.9.8
MEDIUM 4.4 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
01c1458d-3e38-4dbf-bb65-80465ea6d0ad
< 6.5.6
MEDIUM 4.4 The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s… wordfence
← Prev 1341 1342 1343 1344 1345 1346 1347 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top