ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 488 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fb037c9f-5d20-46f6-b1ff-34b9d192bad2
< 3.11.0
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-conten… wordfence
faf45a8d-1017-476e-8af9-2fbe250e8e19
< 2.0.0
MEDIUM 6.4 The Grey Owl Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gol_button' sh… wordfence
faee30bb-ba6e-4d3e-8ca1-79fd676e68f5
< 1.2.14
MEDIUM 6.4 The Meta Field Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
fae39bf9-8ceb-4cb1-afd1-522c885e6ef5
< 4.5.0
MEDIUM 6.4 The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
fadfe181-cc30-407c-baec-dc8f70cffe27 MEDIUM 6.4 The Youtube Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in v… wordfence
fad492f4-7112-4f4f-8825-c42aab552c9b
< 6.3.1.0
MEDIUM 6.4 The PeepSo Core: Photos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in ve… wordfence
facf765a-ddce-485b-adce-99ee22262951
< 1.0.15
MEDIUM 6.4 The All in One Invite Codes plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including,… wordfence
fac90d55-9ae2-48a8-b82b-fe1626556c7b MEDIUM 6.4 The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File upload… wordfence
fac8def6-f5c1-4cd0-bda3-e0f8469accea
< 2.27.1
MEDIUM 6.4 The Arkhe Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2… wordfence
fac89439-bd0a-4772-858d-d11dd0de54b6
< 0.3
MEDIUM 6.4 The Twitter Follow Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'username' parameter… wordfence
fac55d78-fc5e-48d0-843e-511f2bbaf63c MEDIUM 6.4 The Next Event Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
faa6ad51-7b3b-4fe1-95fa-e9b63943d533
< 2.1.2
MEDIUM 6.4 The Flipbox Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flipbox widget… wordfence
faa4f041-4740-4ebb-afb3-10019ce571be
< 1.0.29
MEDIUM 6.4 The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp-piwik… wordfence
fa984d7f-49b9-49c9-9a1c-9e4c8b7f989b
< 3.2.26
MEDIUM 6.4 The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
fa8e1df5-2e8a-4c84-83f8-6f6d53d00356
< 1.3.905
MEDIUM 6.4 The WP eCards plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ecard' shortcode in al… wordfence
fa8aac87-f9bd-4426-85da-e434805c66ec MEDIUM 6.4 The planetcalc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘language’ parameter in all… wordfence
fa821005-9593-4a84-b4b4-af746da4d6b9
< 3.0.0
MEDIUM 6.4 The Contact Form 7 Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
fa701f35-88b6-4ba9-bbda-0cbb1b341d84
< 3.5.2
MEDIUM 6.4 The Video Gallery – YouTube Gallery & Responsive Video Playlist plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
fa63ba9b-7569-4508-92c2-6ae8b9bef3fd MEDIUM 6.4 The GDPR Personal Data Reports plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
fa587df5-9d96-4cac-ae5d-2a0485a3a789
< 1.5.7
MEDIUM 6.4 The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
fa51a7b8-be74-450f-afb8-6a6c5c8afaa4
< 3.2.3
MEDIUM 6.4 The Easy Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in… wordfence
fa43a647-9c54-4838-aeb6-7e4b89d6bf03
< 5.3
MEDIUM 6.4 The Machete plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.2 due … wordfence
fa3cfa43-b1e7-48d6-ad8c-5bc84a0c97c8 MEDIUM 6.4 The Marquee Elementor with Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
fa25e1d2-65eb-450a-967b-3c003fea3464
< 9.1.0
MEDIUM 6.4 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
fa23a535-f290-4517-b203-86e0331f55e4
< 3.2.3
MEDIUM 6.4 The Top 10 – Popular posts plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
← Prev 485 486 487 488 489 490 491 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top