πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 486 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fd3d9ce8-0ebf-490e-8c3a-73883638c3eb MEDIUM 6.4 The NextGEN Gallery Sell Photo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Button Text/Im… wordfence
fd3746dc-bcb1-4f62-b683-844704192b0d
< 3.7.2
MEDIUM 6.4 The NiceJob plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.5 du… wordfence
fd204edd-375e-437d-9964-bbf3b8abeab8 MEDIUM 6.4 The Apply with LinkedIn buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
fd192a52-ae12-4706-b3ea-aa69f7393bb8
< 3.12.6
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label pa… wordfence
fd0e6ca6-f6a7-4e81-aea1-3b59de0173d6
< 2.3
MEDIUM 6.4 The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `b… wordfence
fce76126-0cfd-464f-b644-45d4301e958d
< 2.88.17
MEDIUM 6.4 The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width and heig… wordfence
fcda8a7a-40e3-416e-940a-ba0245dcaa7d MEDIUM 6.4 The ProcessingJS for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pjs4w… wordfence
fccd9631-4703-4e40-9de1-96576cf9c4d8
< 3.3.5
MEDIUM 6.4 The Stars Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
fcc96838-dde5-49f2-ac73-977a8347c455 MEDIUM 6.4 The Custom Colors for Real Estate Manager plugin for WordPress is vulnerable to Cross-Site Scripting via several paramet… wordfence
fcaeae5b-4047-4f09-8197-6ce2c21cc812
< 1.3.3.7
MEDIUM 6.4 The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p… wordfence
fcaea2fb-ebf8-49b4-8cd5-0d9208252a90
< 1.2.6
MEDIUM 6.4 The Events Calendar Made Simple – Pie Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
fca7837c-ad24-44ce-b073-7df3f8bc4300
< 2.9.1
MEDIUM 6.4 The Very Simple Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vsgmap' … wordfence
fca6d469-60e7-4866-a53c-d207817c9204
< 2.5
MEDIUM 6.4 The WP Simple HTML Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
fc98e78b-5388-4573-b2a1-9bad7901d507 MEDIUM 6.4 The Traffic Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in vers… wordfence
fc912831-bbdd-4f8f-a620-47e41b1b731d
< 4.6.2
MEDIUM 6.4 The Tournamatch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trn-ladder-registrat… wordfence
fc870ce5-1352-43f2-b80b-45065ceed750
< 7.7.2
MEDIUM 6.4 The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable t… wordfence
fc7dbdbe-fd0f-404b-9f9f-06e942f60a73 MEDIUM 6.4 The Paged Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode… wordfence
fc712f6b-f11b-4731-8f89-0044830400d6
< 3.5.11
MEDIUM 6.4 The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-… wordfence
fc6634bc-4427-44b6-bf77-d97d5b49e82f MEDIUM 6.4 The Show Posts list – Easy designs, filters and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
fc661cfd-6290-4b36-858a-cf2269b5fcf9
< 1.1.1
MEDIUM 6.4 The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
fc6468bf-37b6-4dd7-b2e5-e880e3cc3c32 MEDIUM 6.4 The GitHub Gist Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of th… wordfence
fc5c10ad-c5e7-4b94-8d5d-112703ad05ea
< 1.16.9
MEDIUM 6.4 The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup body content in versions… wordfence
fc5972d1-f6d6-4708-a9d6-8719639913ef
< 11.0.0
MEDIUM 6.4 The AcyMailing SMTP Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
fc4d4103-a19a-45a5-9059-23eb7f72c84b
< 5.8.1.1
MEDIUM 6.4 The TheGem theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.8.1.1 due to insufficien… wordfence
fc4ccbb0-f94b-4dc1-94bf-03ab3dd84d18
< 2.0
MEDIUM 6.4 The Auto iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'auto-iframe' shortco… wordfence
← Prev 483 484 485 486 487 488 489 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top