πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 485 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fe3cfaf4-67c8-47af-bd58-e8ad27a03fae
< 9.0.1
MEDIUM 6.4 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) S… wordfence
fe275351-a547-440d-9e8c-c464ed333aa9
< 3.0.6.7
MEDIUM 6.4 The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜title’ parameter in all… wordfence
fe175315-99ef-438a-b5b0-a5f190403116
< 2.15.8
MEDIUM 6.4 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
fe1301d9-738b-485f-b8db-c23c16e4f99d
< 3.7.22
MEDIUM 6.4 Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or … wordfence
fe10acf6-2649-4e85-abd1-b6840169eb41 MEDIUM 6.4 The Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions u… wordfence
fdf0b13e-154c-4007-bfc2-5346d906f7ca
< 3.3.6
MEDIUM 6.4 The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the woolentor_quickview_button shor… wordfence
fdeab668-9094-485f-aa01-13ba5c10ea89
< 2.0.27
MEDIUM 6.4 The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up … wordfence
fde110ae-c559-4d45-91c0-a3dd5ff05c4d
< 3.6.0
MEDIUM 6.4 The Inactive Logout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ina_redirect_page_individ… wordfence
fdde4f0d-a4d7-421c-8579-a93941eea712
< 1.3.6
MEDIUM 6.4 The HashBar – WordPress Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu… wordfence
fdd7eef1-6253-4bcf-9249-39078d793aad
< 3.9.35
MEDIUM 6.4 The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
fdd73289-f292-4903-951e-6a89049d39a7 MEDIUM 6.4 The Contact Form by FormGet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formget' shortcode in… wordfence
fdd48c77-c509-4e87-bfc3-0aa422f85ae1 MEDIUM 6.4 The Carousel Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
fdc7e8e2-46d8-4e8f-8277-c704d3c84f36
< 1.2.7
MEDIUM 6.4 The Blogger Buzz theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.… wordfence
fdc614f2-37a6-474a-828a-1f34f98715c5
< 1.4
MEDIUM 6.4 The Web Stories Enhancer – Level Up Your Web Stories plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
fdc39d59-7c9d-4d5d-9fb5-b67d2324adaa
< 3.0.7
MEDIUM 6.4 The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
fdbb60e5-4d67-4deb-94e0-788c1fb0e42f
< 5.4.8
MEDIUM 6.4 The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'zip' parameter in ver… wordfence
fdb184c7-c322-4e05-86db-b398cec1e1b0
< 1.1.30
MEDIUM 6.4 The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… wordfence
fdb15198-68dc-4612-abcc-6b02843f1629 MEDIUM 6.4 The Typed JS: A typewriter style animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜… wordfence
fda268ac-0501-4d86-af90-6c82d4b3c50f
< 2.3.0
MEDIUM 6.4 The Html5 Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
fd929710-bdb4-42e1-b409-df41adc22392
< 3.7.1
MEDIUM 6.4 The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Tabl… wordfence
fd88dbfa-231e-4dce-ac99-23a6a8075102
< 6.0.0
MEDIUM 6.4 The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up … wordfence
fd817fe9-b7be-4252-877a-e9843d62a0a9
< 8.3.3
MEDIUM 6.4 The NEX-Forms - Ultimate Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
fd782479-8eab-439d-9a8e-b4105e49964c MEDIUM 6.4 The Hueman Addons for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and inclu… wordfence
fd6f6a2c-59d3-4091-82ac-0edf9f47ef65 MEDIUM 6.4 The KiwiChat NextClient plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜url’ parameter in… wordfence
fd47e990-b48f-486e-87ac-2bb68d440ba8
< 1.4.72
MEDIUM 6.4 The Motors plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.71 du… wordfence
← Prev 482 483 484 485 486 487 488 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top