🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 484 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ff129569-223d-4d38-9f3a-eb2596214d3a
< 1.5.9
MEDIUM 6.4 The GS Products Slider for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'… wordfence
ff0e8c96-8401-4d01-8185-03967e2aee54 MEDIUM 6.4 The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
ff0d4000-020b-4e22-9362-a8f0f5df321e MEDIUM 6.4 The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `… wordfence
ff065219-7f4f-4445-8dbe-11f4975f7bb9 MEDIUM 6.4 The Playerzbr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'urlmeta' post meta field in all… wordfence
ff0568e2-3a1e-4ed6-835a-37e3d07d7b63
< 2.8.16
MEDIUM 6.4 The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (… wordfence
fefd0e4d-3286-4d05-a715-d76524f1bc2b
< 3.4.1
MEDIUM 6.4 The NGG Smart Image Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
fefa7b93-987d-4c1f-8a49-be22466852b5
< 6.3.16
MEDIUM 6.4 The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordP… wordfence
fee1fef5-5716-49e0-a04e-d0dae527fcfc
< 27.2
MEDIUM 6.4 The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cros… wordfence
fed7becc-2767-40bc-8b56-4032d1e9f85c MEDIUM 6.4 The Peadig’s Google +1 Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
fed0e3bc-1401-410a-805d-1ea3e423024b MEDIUM 6.4 The oEmbed Gist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.9.… wordfence
fec871c7-6559-4152-81be-08ac28b6e173 MEDIUM 6.4 The Arrow Custom Feed for Twitter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
feb9af10-7df2-4eb1-8546-debaa925df42
< 2.4.5
MEDIUM 6.4 The W4 Post List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘w4pl[no_items_text]' param… wordfence
feb51537-4bf7-4607-abbc-614773c55b46 MEDIUM 6.4 The Definitive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
feac5bd3-dfa3-4ad0-b811-7a917970600c
< 1.6.6
MEDIUM 6.4 The Spider Elements – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
fea71287-f92e-43e5-adbf-d89fce437e56 MEDIUM 6.4 The Master Currency WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's currencyconver… wordfence
fe82b7ee-d09b-4eeb-a7d6-914b8b24368b MEDIUM 6.4 The Utilities for MTG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mtglink' short… wordfence
fe6a09b1-cf2c-4d64-9b81-b2cc02e98d45
< 1.3.1
MEDIUM 6.4 The Confetti Fall Animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and… wordfence
fe668f93-f6b7-4824-ad17-024291d8f535
< 1.2.6
MEDIUM 6.4 wordfence
fe647f9a-7467-4534-abcc-40df7b3517e6 MEDIUM 6.4 The Date counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0… wordfence
fe5fd453-b1fc-4d52-bb46-aebd68508891
< 3.10.1
MEDIUM 6.4 The OpenID Connect Generic Client plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'op… wordfence
fe5a963c-df35-4e6e-a381-10e0eb638304
< 2.17.0.2
MEDIUM 6.4 The Knowledge Base documentation & wiki plugin – BasePress plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
fe56adfd-305c-4f40-9250-83f30d189437
< 1.8
MEDIUM 6.4 The SKT Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7 d… wordfence
fe5227f0-3f7f-4d31-8d46-de2eec44b514
< 1.2.2.42
MEDIUM 6.4 The WP Stripe Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… wordfence
fe456de4-4bf3-45aa-938d-8d4561fac44e MEDIUM 6.4 The Magic Edge – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter… wordfence
fe400dbe-43eb-41c1-8e31-c350228e0f8b
< 1.5.2
MEDIUM 6.4 The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Phone', 'Dial Code… wordfence
← Prev 481 482 483 484 485 486 487 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top