🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 727 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1cc2bc18-8182-4716-bb34-ffb574d8c874
< 4.3.11
MEDIUM 6.4 The CM Tooltip Glossary plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
1cbd95bb-6f13-48c9-a51e-5f7bf7a296df
< 3.70.1
MEDIUM 6.4 The Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows plugin for WordPress is vulnerable t… wordfence
1cb8b203-7971-4c92-a499-50b9dc04cd83 MEDIUM 6.4 The Custom Login and Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
1c98e8f4-49b4-4d1e-8e11-e38b676d4af0
< 1.4
MEDIUM 6.4 The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's memberlite_… wordfence
1c93c412-541a-429f-b18e-7b75c8ebdf67
< 1.3.4
MEDIUM 6.4 The Location Weather plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes (such as 'sp_locat… wordfence
1c8e814b-3828-4b3f-a9ad-b3758ab9b109
< 3.14.29
MEDIUM 6.4 The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idx_frame' … wordfence
1c8e6f5e-d403-497d-bedc-d570d35ca00f MEDIUM 6.4 The Cornerstone plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.7.… wordfence
1c894de0-2ea7-4002-9c26-0e3e59744a5e
< 1.8.9
MEDIUM 6.4 The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
1c73724c-c099-49ba-93f4-23e1c8cb4028
< 4.5.3
MEDIUM 6.4 The Save as PDF plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.5.… wordfence
1c6dd146-a99e-4317-a703-de34735317c8 MEDIUM 6.4 The Suki Sites Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all vers… wordfence
1c642df9-559d-4dfa-8c17-4136d9b948d7
< 2.5
MEDIUM 6.4 The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
1c3d4c96-63a7-4f3b-a9ac-095be241f840
< 3.4
MEDIUM 6.4 The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
1c2f4b74-2568-4e5a-b55f-0130096bc19f
< 3.3.57
MEDIUM 6.4 The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
1c13f00e-3048-44cf-8979-2b0b0c508f3a
< 4.3.0
MEDIUM 6.4 The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in ver… wordfence
1c0e5c85-72c3-4f09-aade-ec5a82b9cc41
< 2.0.0
MEDIUM 6.4 The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
1c088264-64a2-4a36-ae3b-fdf60f3837e2
< 2.1
MEDIUM 6.4 The Simple Gallery with Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'c2tw_… wordfence
1bf78bc1-55d7-4230-913f-d7c521225367
< 2.11
MEDIUM 6.4 The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
1bf139cb-4505-4abb-882f-08d7a66aa76f MEDIUM 6.4 The Post Custom Templates Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
1bee1eeb-5354-47c9-9ae1-b1608d87d7bb MEDIUM 6.4 The WP Easy Post Types plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to… wordfence
1beb2a35-0346-4aa1-8cc3-a18a47e82eb3
< 3.7.1
MEDIUM 6.4 The WP Customer Reviews plugin for WordPress is vulnerable to malicious redirects in all versions up to, and including, … wordfence
1be94fa8-ecaf-46e2-a2d6-9d6a4c7343bf
< 2.5.3
MEDIUM 6.4 The WP Job Portal – AI-Powered Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
1be5da88-723a-4386-a73e-3fe90eefb6ba
< 6.8.7
MEDIUM 6.4 The Easy Forms for MailChimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod… wordfence
1be519d5-b505-4b5d-9f14-c8544e8f8298
< 1.1.5
MEDIUM 6.4 The Modern Design Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ paramete… wordfence
1bd77f8e-2210-48c0-a4d9-53eca0abeb00 MEDIUM 6.4 The Kallyas theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.22.0 du… wordfence
1bd0f172-2cd3-4839-9df9-64475554d3b2
< 2.10.35
MEDIUM 6.4 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Services and Post T… wordfence
← Prev 724 725 726 727 728 729 730 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top