🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1082 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
69401e9f-6bd3-49b8-8ebd-6904db680610
< 2.0.0
MEDIUM 5.4 The Responsive Tabs Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_title’ parameter… wordfence
693fbac2-46b8-4771-99b5-6cd97096286e
< 5.5
MEDIUM 5.4 The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in… wordfence
691b7428-73e5-4800-85a1-19daa85aff4e
< 3.11.11
MEDIUM 5.4 The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a mis… wordfence
689f3667-2dda-40a8-8627-d38c6c6816fc
< 2.0.63
MEDIUM 5.4 The Contests by Rewards Fuel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
67e0e59d-879c-434f-9ffb-1b97d8105bfa
< 1.7.2
MEDIUM 5.4 The Cookie Notice & Consent Banner for GDPR & CCPA Compliance WordPress plugin before 1.7.2 does not properly sanitize i… wordfence
67d2364c-6c8b-4b30-8a0e-2f9ee94a3c26
< 2.1
MEDIUM 5.4 The Side Cart Woocommerce (Ajax) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 2.1… wordfence
67790c0b-c078-4955-a175-977a695392fc
< 1.13.4
MEDIUM 5.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter … wordfence
6767cc8e-f327-4891-8d3c-555ba7f5062c MEDIUM 5.4 The Post Teaser plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the init… wordfence
67351a37-a457-48d6-b40a-95a7e3a0d746
< 6.15.16.1
MEDIUM 5.4 The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to … wordfence
670e92d6-4136-48f1-88d1-69a9fa772a65
< 2.11.2.1
MEDIUM 5.4 The Easy Digital Downloads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'start-date' and… wordfence
66efc65e-48d3-4ef9-a369-51448e47686a MEDIUM 5.4 The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… wordfence
66d70cf6-494f-4221-af3b-ee76cf22a305
< 1.8
MEDIUM 5.4 The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS. wordfence
66abfe6b-c706-4e70-b35b-ee04da613933 MEDIUM 5.4 The Remote Content Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'remote_content' … wordfence
66a7ffcc-6929-4c66-bfab-15c0f0097a49
< 1.3.10
MEDIUM 5.4 The Contact Form, Survey & Form Builder – MightyForms plugin for WordPress is vulnerable to unauthorized access due to… wordfence
662116f0-0d32-4d24-868a-a8eccb3ad401
< 25.05.13
MEDIUM 5.4 The The Team Showcase plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to 25.05.13… wordfence
659f5a99-84f4-44b0-8546-445831c7e0d1
< 1.9.6
MEDIUM 5.4 The fitness calculators WordPress plugin before 1.9.6 add calculators for Water intake, BMI calculator, protein Intake, … wordfence
65465de9-c527-4b18-8a52-c9cd2d594f72
< 3.5.2
MEDIUM 5.4 WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an… wordfence
6528041a-0217-43d5-bf29-9208e23aadd9
< 3.4
MEDIUM 5.4 The Weblizar Pin It Button On Image Hover And Post plugin for WordPress is vulnerable to authorization bypass due to a m… wordfence
64cce528-0ad0-45ec-a8f6-e8791b0bece0
< 1.3.60
MEDIUM 5.4 The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_template… wordfence
64ae36a3-d102-4d51-b685-395283155101
< 3.10.0
MEDIUM 5.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3… wordfence
64a833df-1cb8-40a1-9a8f-c53dcf50c877
< 0.9.97.21
MEDIUM 5.4 ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS. wordfence
64a0bfa9-beb3-4926-bfed-af55a101aff1
< 3.1.7
MEDIUM 5.4 The Login With Ajax plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.1.6 d… wordfence
6471b075-8115-4d38-a7dd-2308dca69f15
< 4.2.9
MEDIUM 5.4 The Splitit plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on … wordfence
645ab4b9-e421-4610-b99b-960a7fbb7779
< 2.7.9
MEDIUM 5.4 The Schema Pro plugin for WordPress is vulnerable to unauthorized access, modification, or loss of data due to a missing… wordfence
642e2c46-9e42-4c00-bb91-a43497094e12
< 2.9.11
MEDIUM 5.4 The ListingPro Reviews plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
← Prev 1079 1080 1081 1082 1083 1084 1085 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top