🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 489 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fa1c526d-b751-4461-9e54-e7704ca8ddc3
< 4.5.0
MEDIUM 6.4 The Logo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all ver… wordfence
fa1b55f8-93d8-474c-ab41-e1aef8b258ae MEDIUM 6.4 The MX Time Zone Clocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
fa15ee50-2cbb-4833-b512-0971eaf12ff2
< 7.2.3
MEDIUM 6.4 The Inspiro Pro theme for WordPress is vulnerable to Stored Cross-Site Scripting via the description area in versions up… wordfence
f9ffd35b-833e-4f8d-8563-ef10543bce30 MEDIUM 6.4 The ShopCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.8 d… wordfence
f9fb481f-3f82-4ac7-84d8-be8fda7d1c06 MEDIUM 6.4 The Pull This plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1 du… wordfence
f9eb02f4-ad47-41f2-b3a7-e3f73d7a1bc3
< 4.1.13
MEDIUM 6.4 The PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.12 due… wordfence
f9e85d85-76cd-4606-918b-87f07098c967
< 2.6.32
MEDIUM 6.4 The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
f9de638d-a645-4e4e-bf7d-514692677106 MEDIUM 6.4 The Turn Yoast SEO FAQ Block to Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
f9da9d45-39e2-4b07-baed-1f7d7f67602e
< 28.1.7
MEDIUM 6.4 The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page_title’ parameter in all v… wordfence
f9d50155-73a5-4489-88c5-c7c2a4e30fef
< 1.2.16
MEDIUM 6.4 The Search & Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in ver… wordfence
f9c0ad1e-380e-4b67-b07e-70bf44e4e614
< 3.2.43
MEDIUM 6.4 The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-… wordfence
f9adc83b-b6d3-4ff4-93fb-6236e4a4eaaa
< 2.1.1
MEDIUM 6.4 The Himer theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom CSS code' setting in all vers… wordfence
f9ac2142-7872-4061-9557-d27015403595 MEDIUM 6.4 The Markup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions u… wordfence
f9a60c4e-a524-4a99-858a-14787f37d60c
< 7.2.2
MEDIUM 6.4 The WoodMart theme for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to… wordfence
f9a1e8b8-5c04-44a7-933b-5c1106d5abac MEDIUM 6.4 The Logo Carousel Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
f99e9f01-cc98-4af5-bb95-f56f6a550e96
< 3.6.3
MEDIUM 6.4 The WCFM Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcfm_stores' shortcode in ve… wordfence
f9998485-e272-48fc-b2f1-9e30158d0d16
< 1.2
MEDIUM 6.4 The Neon text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's neontext_box shortcode … wordfence
f98f11da-b0ae-4c00-9708-88d6044abda2 MEDIUM 6.4 The Wp photo text slider 50 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-photo… wordfence
f98b848c-9f97-4d00-97de-7651b9035731 MEDIUM 6.4 The AP Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'adv_parallax_back'… wordfence
f97d97fd-5eac-4fdb-b65a-4c42c3005a2e MEDIUM 6.4 The WP Born Babies WordPress plugin through 1.0 does not sanitise and escape some of its fields, which could allow users… wordfence
f97ced40-c349-43b4-963f-2a49db4bbd4a
< 1.1.7
MEDIUM 6.4 The Insert Headers and Footers Code – HT Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
f97414f7-3544-4ecf-908a-a0215e322e68
< 3.9.2
MEDIUM 6.4 The tagDiv Cloud Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and exclud… wordfence
f972ab72-8e68-4ab3-aa7f-e2816de33554
< 1.1.39
MEDIUM 6.4 The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
f96b23e5-b5f3-4e54-8955-b499648b5675 MEDIUM 6.4 The Storely theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 18 due to… wordfence
f969cb24-734f-46e5-a74d-fddf8e61e096
< 4.4.7
MEDIUM 6.4 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Store… wordfence
← Prev 486 487 488 489 490 491 492 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top