πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 487 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fc4c1809-d79f-4505-8f0a-9ec534c8fea2 MEDIUM 6.4 The Aqua SVG Sprite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio… wordfence
fc329aee-e777-41eb-8799-539c891bd03b
< 2.2.7
MEDIUM 6.4 The Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_title parameter in… wordfence
fc23d52c-68e5-4f5c-9334-acae70fd4c42
< 1.6.2
MEDIUM 6.4 The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them … wordfence
fc1ef15f-ad31-4525-bbe5-bc3cc4485b20 MEDIUM 6.4 The Flask Micro code-editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's codeflask… wordfence
fc1d00c2-8b2f-4d6c-bbd3-085ffb495936 MEDIUM 6.4 The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
fc18643b-028f-46c5-b337-640de427ebdf
< 3.13.1.3
MEDIUM 6.4 The Funnel Builder by FunnelKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
fc0a3870-990c-47dc-b3a9-f436cb199dc4 MEDIUM 6.4 The Trendy Restaurant Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
fbf86da7-621d-4fb7-ba16-d132db5b602a
< 6.2.3
MEDIUM 6.4 The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordP… wordfence
fbece1c4-fbb4-47e5-b5b7-482390bcbd13 MEDIUM 6.4 The Team plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, a… wordfence
fbd67145-5b95-4890-a265-1dd7a029aec6
< 7.4.1
MEDIUM 6.4 The WP Shortcodes Plugin β€” Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
fba6abba-fe29-4a94-bf20-3db78737c275 MEDIUM 6.4 The Widget BUY.BOX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buybox-widget' sh… wordfence
fba3090f-2cc2-4e40-8080-ae83ba321a67 MEDIUM 6.4 The Live Photos on WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_src', 'img… wordfence
fb8ac14b-ac65-4169-bef5-36e160e00d62
< 2.5.0
MEDIUM 6.4 The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in a… wordfence
fb7d4eee-fd81-4d9d-8d8d-a56870b27874
< 1.20.33
MEDIUM 6.4 The Vantage theme for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery block text content in versions … wordfence
fb6783b4-f7a5-4f8f-a8d0-5f5c7f91f687
< 1.4.1
MEDIUM 6.4 The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
fb62f4c2-ce9f-4958-8b83-cc0d5f4d4647
< 2.4.9
MEDIUM 6.4 The Chatbot for WordPress by Collect.chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_in… wordfence
fb53d658-c596-4d5c-a7be-d7c5415f4733
< 1.3.21
MEDIUM 6.4 The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
fb4b5165-35a6-47e9-922e-b244b0d006e4
< 2.4.41
MEDIUM 6.4 The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown URL param… wordfence
fb3e0251-c3b7-4360-87f3-7e4612d4f285
< 3.16.3
MEDIUM 6.4 The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability c… wordfence
fb364d54-bd44-426f-8f11-8ee5a7527c5d
< 2.2.12
MEDIUM 6.4 The WP Club Manager – WordPress Sports Club Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… wordfence
fb2777c7-ccc6-4435-9862-c060ff6ceed5 MEDIUM 6.4 The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
fb147805-8257-4e61-8922-331d7d5a68cb MEDIUM 6.4 The StoreBiz theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.32 d… wordfence
fb1392b4-326a-4a54-be04-972b0716b1de
< 2.2.2
MEDIUM 6.4 The Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.1 du… wordfence
fb051c9a-939c-44cb-8af2-bf841c334cf8
< 1.1.9
MEDIUM 6.4 The Thim Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
fb04865e-e238-4227-bd9b-e05dcb0d3c53
< 1.0.8.5
MEDIUM 6.4 The EO4WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.8.4 du… wordfence
← Prev 484 485 486 487 488 489 490 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top