πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1084 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5ee7b4d8-c397-41f6-981f-9a010e4ab2f1
< 1.7.1018
MEDIUM 5.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Count… wordfence
5eab8a5d-8eb8-495f-a953-b468360cc5d5
< 5.7.12
MEDIUM 5.4 Advanced Custom Fields before 5.7.12 fails to sanitize user-supplied input before passing it to the unserialize() functi… wordfence
5e7b29aa-9dff-420b-8f3e-2beca0b19593
< 2.1.1
MEDIUM 5.4 The StreamCast – Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its … wordfence
5e0a7108-15ef-42d0-adce-fd5b0e6faf3c
< 3.10.0
MEDIUM 5.4 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve… wordfence
5de937cc-da05-4b95-807d-dc19a8b7d6b0 MEDIUM 5.4 The Child Theme Generator plugin for WordPress is vulnerability to Cross-Site Request Forgery in versions up to, and inc… wordfence
5de488a2-72d6-4eeb-9b92-7f5bea1ee4ff
< 2.2.1
MEDIUM 5.4 A stored cross-site scripting vulnerability has been discovered in : Simply Gallery Blocks with Lightbox (Version – 2.… wordfence
5d58a6a4-de2c-485f-a8b0-7a7d144fbf3c
< 1.1.2
MEDIUM 5.4 The Feather Login Page plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check… wordfence
5d463709-8afd-4db6-bd0a-524d7b27f4ea MEDIUM 5.4 The Psychological tests & quizzes plugin is vulnerable to Cross-Site Scripting due to missing sanitization on the wpt_te… wordfence
5d3bcd2c-4cdd-4a11-83a5-b727a2b2b6a6 MEDIUM 5.4 The Admin Block Country plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
5d2d8ba7-269b-4830-8551-c2291199fb67
< 1.10
MEDIUM 5.4 The M Chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.4 du… wordfence
5d21aad7-dbee-4204-afbd-0a5fdeaca50e
< 2.2.2
MEDIUM 5.4 The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
5d0d44bb-a6b9-44cc-ba38-0e28ad318594
< 3.10
MEDIUM 5.4 The Trade Runner plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, an… wordfence
5cf6cbba-0e0c-4d2c-90d0-d7e0a5222df2
< 1.8.97
MEDIUM 5.4 The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, … wordfence
5cf17465-59a9-475d-bd1a-9e3623190926
< 7.3.6
MEDIUM 5.4 The themify-ultra theme for WordPress is vulnerable to unauthorized access, modification or loss of data due to a missin… wordfence
5cc92354-55f4-4799-a974-14fa6fb584b9
< 1.4.12
MEDIUM 5.4 The Support Genix – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Ob… wordfence
5cc590fe-94c8-47cc-bd5b-eef70da138b1
< 1.8.8
MEDIUM 5.4 The Photo Gallery by 10Web plugin for WordPress is vulnerable to open redirect in versions up to 1.8.7. This is due to i… wordfence
5cba7026-04e4-4ace-9298-0177902b7529
< 4.6.5.3
MEDIUM 5.4 The Newsletters for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜id’, 'method', 'value', 'ord… wordfence
5ca21247-c443-4808-8397-790669453bfc
< 1.26
MEDIUM 5.4 The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
5c7d4401-33aa-43c4-8659-a5664b3cf1da
< 3.12.7
MEDIUM 5.4 The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS. wordfence
5c3ca2d7-7af9-401f-bc5a-1796c6253cb0
< 3.0.0
MEDIUM 5.4 The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin… wordfence
5bda56c3-56ad-40d7-b743-0b69512ec460 MEDIUM 5.4 The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
5bd9f312-99e1-4dc2-855d-90339c2e24da
< 3.6.2
MEDIUM 5.4 The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. Th… wordfence
5bb45de4-2c83-4c77-aec0-f28ade966468
< 4.3.5
MEDIUM 5.4 The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low… wordfence
5b98173e-0b89-44f9-a238-34a36ed422ac
< 2.1.3
MEDIUM 5.4 The Sticky Header Effects for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
5b4dc917-0d59-4163-a613-49afc1dc4d33
< 1.20.3
MEDIUM 5.4 The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPre… wordfence
← Prev 1081 1082 1083 1084 1085 1086 1087 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top