πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 528 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d2c70f93-4045-4c91-b412-d8b0ba240bc6 MEDIUM 6.4 The Coub plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4 due to … wordfence
d2c3ea1a-ecf4-4af4-9c87-a6cdede84087 MEDIUM 6.4 The Simple Meta Tags plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
d2bac05e-ecd0-427b-90a0-6cf78175cd19 MEDIUM 6.4 The The Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'the_tooltip' shortco… wordfence
d2b9f92f-be68-4be2-a7e0-3ff5fcec641d MEDIUM 6.4 The ListingPro Lead Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
d2b1e973-f22d-4e69-b3b8-d6ea5df3f047
< 1.12.5
MEDIUM 6.4 The Envira Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in versions u… wordfence
d2b0de76-14be-414e-bbdb-1188f3516633
< 3.1.1
MEDIUM 6.4 The Quotes llama plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1… wordfence
d2a7f4b0-2218-499b-8674-65ab8aced6a9
< 2.3.6
MEDIUM 6.4 The WP Cassify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.5… wordfence
d29a3a29-1fb5-41c8-9516-16bd9fc0018d MEDIUM 6.4 The Show YouTube video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'syv' shortcod… wordfence
d292c4ff-123e-4aa0-8ce8-d2bb2f3c6e02
< 3.4.23
MEDIUM 6.4 The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key],… wordfence
d2922c85-7e16-48a1-9c43-c1a9d34571e0
< 1.8.7
MEDIUM 6.4 The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's … wordfence
d2716f7e-ae73-482a-acf7-772884f0b3ab
< 3.7.22
MEDIUM 6.4 Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery. wordfence
d27090ca-4a6d-4533-a013-674cfc756d25 MEDIUM 6.4 The Charity-thermometer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
d26c7cd4-7548-421f-ace0-7f9dce16b0dc
< 12.9.2
MEDIUM 6.4 The The7 β€” Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
d244bc34-821d-41bf-9efb-39a4644c6b1c
< 2.14.3
MEDIUM 6.4 The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerabl… wordfence
d22d9414-2df9-4528-a426-dce6e83f8d44
< 3.2
MEDIUM 6.4 The Jquery news ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jquery-news-ticker' shortc… wordfence
d227d4e4-2899-434c-8b93-8d93a89b1b1b MEDIUM 6.4 The Sherk Custom Post Type Displays plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' sh… wordfence
d21ca709-183f-4dd1-849c-f1b2a4f7ec43
< 20230901
MEDIUM 6.4 The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [usp_gallery… wordfence
d21aeeb6-2e7d-426e-82c5-ff65e33bc5cb
< 3.2.8
MEDIUM 6.4 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Vide… wordfence
d21a12b4-2f9d-4ae3-a5f6-1ba90fab43a2 MEDIUM 6.4 The Weluka Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'weluka-map' shortcod… wordfence
d20c09ee-bd75-4f96-b0b9-2cf6f87aa4cb
< 2.1.3
MEDIUM 6.4 The Goodlayers Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio… wordfence
d1ee155a-3b4d-4b32-a1ec-86e0575e0ad8 MEDIUM 6.4 The Citations tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'code' parameter in the 'c… wordfence
d1d571e3-cf6d-4e9b-a3d7-e7e19497b5a9 MEDIUM 6.4 The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspcheck' shortcode in v… wordfence
d1d113fd-efb4-4918-a5df-153e549836d6
< 3.9.0
MEDIUM 6.4 The Inline Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
d1c514dd-132f-4e42-a512-bb0cf24da937
< 2.6.6
MEDIUM 6.4 The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i… wordfence
d1c3ddae-046a-4080-ac2b-90fb89fbff7b MEDIUM 6.4 The Responsive Tabs For WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
← Prev 525 526 527 528 529 530 531 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top