πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1059 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e5d81318-c9da-4626-acfa-f092d2ce5fe9 MEDIUM 5.4 The News Element Elementor Blog Magazine plugin for WordPress is vulnerable to Missing Authorization in all versions up … wordfence
e5a2ed81-254e-460c-b3a4-0cb38e089142
< 3.14.1
MEDIUM 5.4 The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Sl… wordfence
e58a45c4-06cb-4b2b-97f2-a614fc230942 MEDIUM 5.4 The Alter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This i… wordfence
e54f1a23-0b1f-4b0b-909e-e877e4ee2c86
< 2.0.3
MEDIUM 5.4 The Majestic Before After Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_label'… wordfence
e5495b4c-a1ac-4860-83a7-686d9436d983
< 4.4.9
MEDIUM 5.4 The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restri… wordfence
e52d8b5e-727f-474a-a255-c24033db17d8
< 1.3.6
MEDIUM 5.4 The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulne… wordfence
e52b27fa-10e8-43d0-be29-774c2f5487ae
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
e4a2c3cf-0785-4bf0-9ad8-0d2479545067
< 1.9.3
MEDIUM 5.4 The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users wit… wordfence
e485f089-689f-4f73-bb0d-eca6815388be
< 3.2.4
MEDIUM 5.4 The BuddyBoss Media plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the album description input… wordfence
e3ec9b11-e689-4796-8b05-59ab05a98184
< 1.2.4
MEDIUM 5.4 By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to … wordfence
e3e2efbf-11ac-4a85-8136-cb40468089e1
< 1.3.11
MEDIUM 5.4 The Kieran O'Shea Calendar plugin before 1.3.11 for WordPress has Stored XSS via the event_title parameter in a wp-admin… wordfence
e3ce0eca-5ec3-4af9-bc83-2f973b18e7f7
< 6.2.0
MEDIUM 5.4 The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has Cross-Site Scripting via wp-admin/admin-ajax.php?act… wordfence
e32d9104-5a39-4455-b76a-e24ae787bdfd
< 2.33.4
MEDIUM 5.4 The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. Th… wordfence
e2e8d217-51a7-4653-bb23-c53f5c75cb85
< 2.5.7
MEDIUM 5.4 The Product Slider for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capabilit… wordfence
e2e39fe4-8c22-4da6-8cb6-737ddd4dc36e
< 2.9.9
MEDIUM 5.4 The Elementor Website Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An aut… wordfence
e2cc2776-9496-42b5-a242-c572ae5462fb
< 2.7.4.3
MEDIUM 5.4 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to DOM-Based Reflected Cross-Site Scrip… wordfence
e27bd526-1a5f-4628-8bb2-1741496f897f MEDIUM 5.4 The WP Log Viewer plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability ch… wordfence
e2152db7-be9a-4e09-97cf-60445d87b576
< 4.2.3
MEDIUM 5.4 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on … wordfence
e1be11c5-0a44-4816-b6bf-d330cb51dbf3
< 1.23.11
MEDIUM 5.4 The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
e1b80852-a221-4c2c-b76d-8bdcd1e0f1ad
< 4.5.2
MEDIUM 5.4 The Microsoft Azure Storage for WordPress plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Deletion in… wordfence
e1b473fd-2444-4a54-b558-4656634a6903
< 1.1
MEDIUM 5.4 The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,… wordfence
e17dd3e7-9bd9-4852-9512-72fe1e40f86a
< 2.3.7
MEDIUM 5.4 The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allow… wordfence
e16b8686-a502-4a73-b955-10f2800fd5dc
< 5.0.7
MEDIUM 5.4 The Team plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in ve… wordfence
e166a7db-45f7-4a0d-9966-dbec9ade204a
< 4.8.1
MEDIUM 5.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button URL in a… wordfence
e122d75b-0bde-4886-a8e0-d07a535fc967
< 1.9.0
MEDIUM 5.4 The Apollo13 Framework Extensions plugin for WordPress is vulnerable to missing authorization due to a missing capabilit… wordfence
← Prev 1056 1057 1058 1059 1060 1061 1062 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top