🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1063 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2026-5077 MEDIUM 5.4 The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and includ… nvd
CVE-2026-2732
< 4.1.8
MEDIUM 5.4 The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capa… nvd
CVE-2026-2694
< 6.15.16.1
MEDIUM 5.4 The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to … nvd
CVE-2026-2284 MEDIUM 5.4 The News Element Elementor Blog Magazine plugin for WordPress is vulnerable to Missing Authorization in all versions up … nvd
CVE-2026-2127 MEDIUM 5.4 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to unauthorized arbitrary shortcode execution in all ve… nvd
cf96887c-6e0d-43d9-a3f2-88981adb4c98
< 1.3.2.5
MEDIUM 5.4 The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.… wordfence
ceeefc3f-1cb7-48df-9978-258f015d93c7
< 1.13.6
MEDIUM 5.4 The Easy Image Collage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check… wordfence
ceb25902-9dcb-4aba-bee2-893f5cdadebc MEDIUM 5.4 The The xsmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, … wordfence
ceb08ca9-e512-4a97-b323-cd9447b8bcac
< 1.9.17
MEDIUM 5.4 The Academy LMS plugin for WordPress is vulnerable to unauthorized access due to insufficient validation on the enroll_c… wordfence
ce8e5635-a343-40b4-838c-21b942af5242
< 1.2.13
MEDIUM 5.4 Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allo… wordfence
ce5f4960-e47c-4926-97f2-8c94c438a4e0
< 3.3.12
MEDIUM 5.4 The “Sina Extension for Elementor” WordPress Plugin before 3.3.12 has several widgets that are vulnerable to stored … wordfence
ce4ca9c6-7ffd-4170-9004-f7bc3ad15df0
< 2.6.2
MEDIUM 5.4 Stored XSS in the IMPress for IDX Broker WordPress plugin before 2.6.2 allows authenticated attackers with minimal (subs… wordfence
ce3a3802-ea03-4840-8da2-fd292a0c4099 MEDIUM 5.4 The WP Nice Loader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
ce2edda2-7707-415e-9493-e1067a421f54 MEDIUM 5.4 The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_… wordfence
ce060989-ce70-49ac-921c-a687bc944090
< 4.0.0
MEDIUM 5.4 The Mass Delete Taxonomies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
cdee0cd8-b83b-4436-aebe-533f5af03ef1
< 1.13.5
MEDIUM 5.4 The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Req… wordfence
cde8c669-c9bb-4ecc-b589-3cda8757dfc6 MEDIUM 5.4 The Logaster Logo Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
cdd464ad-24bc-4922-8bfa-ac42fbe60b52
< 1.3.60
MEDIUM 5.4 The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_requir… wordfence
cd4d67cd-5fb0-425d-8b22-c69ebb0ffa72
< 1.3.53
MEDIUM 5.4 The Falang multilanguage for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a … wordfence
cd4c2c11-2d73-48b4-8e7e-e281451973a2
< 5.0
MEDIUM 5.4 The The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Cu… wordfence
ccee37f3-4120-46fb-a201-346994d4d55b
< 1.4.1
MEDIUM 5.4 The Simple Photo Feed plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
cca2bd96-ac3c-480c-8fe7-fb5227a093ae
< 5.10.3
MEDIUM 5.4 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… wordfence
cbb31cc2-d221-4e2c-a4de-e954d3c9069d
< 1.4.0
MEDIUM 5.4 The Kenta Blocks – Responsive Blocks and block templates library plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
cb7335c0-b6ed-43bb-91b7-870093d14cb8
< 7.2.0
MEDIUM 5.4 The Image Regenerate & Select Crop plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… wordfence
cb7316cd-8a15-4b81-b57c-b8e4adcaf1ef MEDIUM 5.4 The WHA Crossword plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
← Prev 1060 1061 1062 1063 1064 1065 1066 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top