🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 483 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
012a558c-1f80-4f36-85d9-905f4ed0b6cb
< 2.3.37
MEDIUM 6.5 The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to Insecure Di… wordfence
00aa4e06-66ec-46cb-9a24-e63d64810d83 MEDIUM 6.5 The Classic Widgets with Block-based Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
00675945-4a7f-49f5-8bde-bb0669edecab MEDIUM 6.5 The Ni CRM Lead plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.3.0 due to i… wordfence
00375b21-0395-46cc-a79a-47409769d503 MEDIUM 6.5 The Theme File Duplicator plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3… wordfence
001a7d43-4b00-42e9-bb0c-94a9d5721166
< 7.2.1
MEDIUM 6.5 The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the Buddy… wordfence
fffd6fc5-1578-414c-bb36-4f5dc0f27e19
< 1.0.22
MEDIUM 6.4 The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and inc… wordfence
ffeb766f-3684-4eec-bacb-bbf0d434aba0
< 1.58.4
MEDIUM 6.4 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the onclick paramete… wordfence
ffde541b-5e2b-437b-a123-8522beca52ef MEDIUM 6.4 The Current Book WordPress plugin through 1.0.1 does not sanitize user input when an authenticated user adds Author or B… wordfence
ffd3ecc8-8b76-453f-b2e9-a9c70c58edbf
< 1.4.0
MEDIUM 6.4 The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribut… wordfence
ffce535f-620d-40f8-a944-11ea87a67380
< 4.4
MEDIUM 6.4 The Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up… wordfence
ffc82708-b04d-4fba-9a79-594ad25dc965
< 3.20.1
MEDIUM 6.4 The Flatsome Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's shortcodes in all versions… wordfence
ffbb6268-5461-4291-be76-10ba060e352e
< 2.7.7
MEDIUM 6.4 The Participants Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
ffa3b85c-7d08-4f6a-889e-b75620f72a1a
< 2.4.3
MEDIUM 6.4 The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
ffa252d6-0fe2-4d1f-802f-b902084822a7
< 3.7.15
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php… wordfence
ff7f92ec-0412-414f-9afe-e1ba4fa0dbae
< 0.20
MEDIUM 6.4 The m1.DownloadList plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
ff6ff104-44c8-49a9-bebd-abb82e8e1cd6
< 7.11.7
MEDIUM 6.4 The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions u… wordfence
ff6932c6-f3ec-46a8-a03b-95512eee5bf1
< 9.7.9
MEDIUM 6.4 The Shareaholic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shareaholic' shortcode in version… wordfence
ff4c217c-3a61-4f96-a698-b7fba1294ace
< 1.5.2
MEDIUM 6.4 The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
ff41796a-0ba8-468f-8b79-274064da154e MEDIUM 6.4 The Radius Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subHeadingTagName’ para… wordfence
ff3a69a3-dc74-4e44-b791-d02b0f5ebedf MEDIUM 6.4 The Optimate Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0… wordfence
ff32bc6a-0d1e-47d0-8264-946e72266b72
< 3.3.1
MEDIUM 6.4 The Ultimate Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
ff2a14b1-8752-4edf-a807-88aab453451d MEDIUM 6.4 The WordPress Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s)… wordfence
ff197a1c-3d5b-497f-b35c-40249a426e49 MEDIUM 6.4 The Multiple Votes in one page plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
ff150706-5fbf-4881-976b-89fdaf637fb1
< 2.11.4
MEDIUM 6.4 The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all… wordfence
ff13b72f-7175-42c1-a24a-2570dd57bb3e MEDIUM 6.4 The RS WP Book Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
← Prev 480 481 482 483 484 485 486 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top