πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 491 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f84ab165-4fff-4c57-857d-5259a92d5690
< 2.1
MEDIUM 6.4 The SKT Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0 d… wordfence
f84660c8-9dfc-4c1d-9585-edb3b28f1858
< 1.5.3.3
MEDIUM 6.4 The Shipment Tracker for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
f83db067-843f-4dd8-b5d1-83e95c6c88cc
< 2.8.3.6
MEDIUM 6.4 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
f83d0d4c-b7b2-4788-8e43-9155b5d5a4f7 MEDIUM 6.4 The Music Press Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
f838dbc9-b31e-46c6-b615-4e8ece9a9cfc
< 2.6.6
MEDIUM 6.4 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sto… wordfence
f8343c1e-385c-4301-8186-4c8fb3e270f5 MEDIUM 6.4 The Blocks Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
f8310fae-813c-4325-9ae6-f0ea470e0168
< 3.1.17
MEDIUM 6.4 The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers… wordfence
f821f78e-d56e-4aad-8d05-ee15b49742a0
< 2.5.5
MEDIUM 6.4 The WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.4 … wordfence
f81df26f-4390-4626-8539-367a52f8a027
< 1.5.2
MEDIUM 6.4 The Simple Like Page Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sfp-page-plugin' shor… wordfence
f8147f63-91a5-457c-8259-8e4ddf5c67e4
< 119
MEDIUM 6.4 The Simple URLs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 119 … wordfence
f81355fa-5b12-4b03-bd3d-f9e2cb734390
< 1.2.2
MEDIUM 6.4 The MagicPost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wb_share_social shortco… wordfence
f80af397-72d5-4446-b43f-3be26657b73e
< 2.6.4
MEDIUM 6.4 The Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates plugin for WordPress is vulnerab… wordfence
f807b605-68a8-4340-a275-776eac0936fa
< 1.0.16
MEDIUM 6.4 The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Animated Box widg… wordfence
f7bf63a9-3c99-43fc-a973-d75f2469fb7b
< 2.7.2
MEDIUM 6.4 The Widget Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
f796ade5-db48-4334-9a76-15326f62c9a5 MEDIUM 6.4 The Reuse Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'reuse_builder_single_post_t… wordfence
f7960d2b-8691-4a33-bab9-dc637743f12a MEDIUM 6.4 The Blog Summary plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.1… wordfence
f77a284f-ac63-47b7-b5db-b6d0ccd03541 MEDIUM 6.4 The Bonway Static Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
f7773b98-537f-4f4e-98d6-db61d2bffe8c
< 5.8.15
MEDIUM 6.4 The Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for Wor… wordfence
f7580145-03da-4aff-b804-39125e7daad1
< 2.1.9
MEDIUM 6.4 The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
f75093a5-e0cc-4d3b-bdef-a65561127b3d
< 8.6.1
MEDIUM 6.4 The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, a… wordfence
f7509053-fc70-420a-b998-b7158732c147
< 2.0.1
MEDIUM 6.4 The Surbma | MiniCRM Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode … wordfence
f742dc8a-530b-41e6-ac82-52770952f619 MEDIUM 6.4 The WE Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.5 … wordfence
f735f05d-8178-46bd-894d-49ccfb31d304
< 1.6
MEDIUM 6.4 The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG F… wordfence
f72cbcd8-13ad-4f19-a72c-2c5472e434f1 MEDIUM 6.4 The Feedburner Optin Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
f723be00-79f1-4a24-8502-2c5844ccc5de MEDIUM 6.4 The Responsive Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'somryv' shortc… wordfence
← Prev 488 489 490 491 492 493 494 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top