πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 490 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f962bfb4-bb5e-4069-a1a4-7e28335780e6
< 2.1
MEDIUM 6.4 The Christian Science Bible Lesson Subjects plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
f959289c-ad24-4768-b62d-a9f35a84ea93
< 2.1.1
MEDIUM 6.4 The CC BMI Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
f94a1671-11f8-4a05-b950-a068edf29f43
< 1.25.11
MEDIUM 6.4 The e2pdf plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.25.05 du… wordfence
f93d70e4-01c5-44e8-b7d5-0837bee53b8d
< 2.5.3
MEDIUM 6.4 The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up … wordfence
f931cf8e-01dd-4f0b-ac86-6e0654fd1597
< 5.6.2
MEDIUM 6.4 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… wordfence
f926728d-2752-4aa4-b1d7-5805e3b256c9
< 2.6
MEDIUM 6.4 The Select Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 2.6 due to insuffici… wordfence
f920d63e-2101-4192-8916-be2d42929a54
< 3.7.1.1
MEDIUM 6.4 The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.0 … wordfence
f8f7a00e-9cb4-4640-bda9-0cd7341d0c41 MEDIUM 6.4 The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings… wordfence
f8ec4c5e-fb24-4b74-9ed8-0a9060625aba
< 1.17.0
MEDIUM 6.4 The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.… wordfence
f8e4df9d-ff7c-403f-abc9-0fad8d7e44d3 MEDIUM 6.4 The WP Social Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
f8e2305f-40ce-4278-a4ea-ddbeb8806777
< 1.1.26
MEDIUM 6.4 The BookingPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1… wordfence
f8e0cb68-3882-4337-ba3f-a817fe7794d2 MEDIUM 6.4 The Ultimate Live Cricket WordPress Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
f8c18b0d-15fe-45d6-9915-85d38803c117
< 1.2.23
MEDIUM 6.4 The Email Subscription Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's print_em… wordfence
f8c15f90-1b38-4e64-aa41-e1473be5b07b MEDIUM 6.4 The VR Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.1 d… wordfence
f8bc8863-04a9-4631-9510-624f98ea1e75
< 2.4.4
MEDIUM 6.4 The WordPress Comments Import & Export plugin for WordPress is vulnerable to unauthorized modification of data due to a … wordfence
f8ba38c3-51d2-43a7-89ff-c72a8edc946b MEDIUM 6.4 The CPO Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all … wordfence
f8b09933-9634-4a8a-a899-ba500979e5aa
< 2.1.3
MEDIUM 6.4 The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters f… wordfence
f8b089d9-f509-4ebe-9587-aa54c52c35bd
< 2.3.8
MEDIUM 6.4 The Ultimate Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
f898ab34-2d63-458d-b19b-4e2b6f4a0f3b
< 6.4.6
MEDIUM 6.4 The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6… wordfence
f891a6c8-3d06-432e-8651-bb689015af1c
< 4.10.32
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's menu… wordfence
f88f065d-14ca-4547-9a41-f9177979a9ed
< 5.4.1
MEDIUM 6.4 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Store… wordfence
f88ef4cf-3f22-40e0-b651-59cb40f148fd MEDIUM 6.4 The TJ Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versio… wordfence
f884aa09-9f5e-4602-8ba3-3a1268c9c8b4 MEDIUM 6.4 The OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable … wordfence
f86e58a6-b713-43f2-97e1-3b7c9a505797
< 1.2.5
MEDIUM 6.4 The SaasPricing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.… wordfence
f86c6ada-112b-4b1f-b1ac-7dd4920953c8
< 3.1.1
MEDIUM 6.4 The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via S… wordfence
← Prev 487 488 489 490 491 492 493 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top