🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 726 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1d9ff834-8a11-4ec7-9371-15d56bc84106 MEDIUM 6.4 The Clicface Trombi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nom’ parameter in all… wordfence
1d9c4c5c-78cd-4c58-911a-fb67de0c1dca
< 1.7.9
MEDIUM 6.4 The WP Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in v… wordfence
1d99c8a8-daeb-402b-990d-6bacf6e9a780 MEDIUM 6.4 The Woodpecker for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_name' param… wordfence
1d95ec4b-0cbc-49c6-821e-7050d8045159
< 2.0.0
MEDIUM 6.4 The Slotti Ajanvaraus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slotti-embed-g… wordfence
1d8b79cc-287e-420b-8eb8-6345a62e9fb9 MEDIUM 6.4 The Oboxmedia Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_widget' and 'after_w… wordfence
1d852dba-39ea-4cc9-9fcf-7f2ac3e1b5d0 MEDIUM 6.4 The Stock Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_height' and 'image_widt… wordfence
1d8331ce-666d-4d5a-b9cd-08562e3eea43
< 1.7
MEDIUM 6.4 The Wonder PDF Embed WordPress plugin before 1.7 does not escape parameters of its wonderplugin_pdf shortcode, which cou… wordfence
1d72ff0c-cbee-42a6-8bee-29a5e522a18d MEDIUM 6.4 The Restaurant Reservations plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
1d667556-4cab-4f92-aa43-75e7722b3af6
< 1.5.9
MEDIUM 6.4 The Interactive Geo Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s)… wordfence
1d641e9e-e690-48ff-a28b-f4068d372aab MEDIUM 6.4 The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.9.91… wordfence
1d4ecdfd-3970-4b87-831b-82bfb5a3c390
< 3.1.32
MEDIUM 6.4 The Icegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.31 d… wordfence
1d45dcf3-9d1b-4370-ac63-e19f60ef9df6 MEDIUM 6.4 The Luzuk Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.1… wordfence
1d445043-f5dd-438c-968c-eedd096089ae
< 2.8.1
MEDIUM 6.4 The Membership For WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
1d305711-7a84-46c2-b333-02f5a745d76c
< 2.0.4
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 allows remote attackers to inject arbitrary… wordfence
1d2f973a-1fb3-4c75-8c33-6d1fadf9c906
< 1.5.1.2
MEDIUM 6.4 Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow re… wordfence
1d2f17b9-efe9-40be-8b01-1eb73ccaf212
< 1.5.2
MEDIUM 6.4 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
1d28e118-07d3-483e-87b8-66ccdb79e879
< 3.14.4
MEDIUM 6.4 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is… wordfence
1d119ee0-4c16-46b1-ae45-8e0c6de0081b
< 1.1.16
MEDIUM 6.4 The El mejor Cluster plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
1d07eefc-f406-4da4-addb-559caa6dc208
< 3.0.1
MEDIUM 6.4 The Feed Them Social plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘access_token’ parame… wordfence
1cfbb817-1bb2-4829-9a63-d8e579053000
< 2.1.10
MEDIUM 6.4 The StreamWeasels Online Status Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '… wordfence
1cf5c5e0-3194-44a5-b6a7-77b7e8fc1ab9
< 2.6.0
MEDIUM 6.4 The Doppler Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
1cf3190c-e247-4bcc-99e0-2ab2d2fa0590
< 5.9.16
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
1cf23d79-5bd3-4224-835d-174653ddd504 MEDIUM 6.4 The DIOT SCADA with MQTT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'diot' short… wordfence
1cda411b-b277-4b4d-9087-dadede4b67dd
< 1.6.1
MEDIUM 6.4 The Contact Form Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [xyz-cfm-for… wordfence
1cd877e6-e000-437d-ba9f-0640350277e4
< 2.12.9
MEDIUM 6.4 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu… wordfence
← Prev 723 724 725 726 727 728 729 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top