🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 492 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f7222c7e-939a-4666-9d01-f715d2827954
< 4.10.17
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
f72107e9-95e3-4dab-b1a9-6c91cd6c6eb7
< 7.8
MEDIUM 6.4 The AR For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
f7140053-a3c3-44c4-bc83-2e9b9e8853d6 MEDIUM 6.4 The Instant-Quote.co Quotation Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attr… wordfence
f70ba568-b013-4177-928a-eefb606333ee MEDIUM 6.4 The Tweaker5 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the the… wordfence
f702fef0-8f07-4c94-bbf7-394d66f9ddde
< 1.22.24
MEDIUM 6.4 The Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
f6fce60b-2920-493a-be29-fa78193db875
< 1.2.6
MEDIUM 6.4 The Typing Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.… wordfence
f6e8d21a-8c67-4e35-b18e-e100f31b2863
< 1.1.10
MEDIUM 6.4 The Content Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in ver… wordfence
f6e6fda8-e998-4087-8a21-9edb2a0249c8
< 3.8.3
MEDIUM 6.4 The All-in-One Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video sh… wordfence
f6d3c88d-d0a1-4f27-8a9c-df35235b34dc
< 5.9.8.2
MEDIUM 6.4 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
f6ccddd4-89fe-4786-917b-944185b4510b MEDIUM 6.4 The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blog-card' shortcod… wordfence
f6cb6fbc-456d-4912-a574-cb25ab16df3a MEDIUM 6.4 The WP Scriptcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter in all versi… wordfence
f6c14c65-a47c-4dc1-9d5a-f804061152e4 MEDIUM 6.4 The ShortCodes UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all ve… wordfence
f6ba2907-36f4-4c4d-9e25-d13d32e28690
< 3.4.6
MEDIUM 6.4 The Custom Post Type Attachment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pdf_… wordfence
f6b740bf-ac9e-4e62-8f4c-a42c4857646f
< 3.2.22
MEDIUM 6.4 The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
f6afe4b6-c38c-46fa-82d5-95cb35c2c30f
< 1.3.1
MEDIUM 6.4 The SB Chart block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter i… wordfence
f6af1e90-9bad-470b-9e00-137000c0450c
< 6.7.0
MEDIUM 6.4 The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, an… wordfence
f6929fdc-a5b1-4c71-9291-3fafa9381cf2
< 7.5.0
MEDIUM 6.4 The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
f6816cb4-0fad-417a-a980-d35a734bce13
< 1.4.0
MEDIUM 6.4 The GS Portfolio for Envato plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode… wordfence
f674d3bf-9927-48d9-85c7-34946e8a2eeb
< 1.0.2
MEDIUM 6.4 The Sheet to Table Live Sync for Google Sheet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
f6655dc6-cf03-40c4-8fb2-fce6cfb069a6
< 1.2.4
MEDIUM 6.4 The Icon List Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
f65834c6-6da7-4033-aa2a-a4926d6c955d MEDIUM 6.4 The Neighborly theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the t… wordfence
f6360ef9-b54d-474b-8c0b-65b62841a283 MEDIUM 6.4 The Open Currency Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
f616df94-7839-49db-baa5-88f8f1de208f
< 3.5.4
MEDIUM 6.4 The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem… wordfence
f610d7ef-fb7c-4c3b-bde2-d7071331be70
< 2.6.4
MEDIUM 6.4 The Webinar and Video Conference with Jitsi Meet plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… wordfence
f60df43a-eef3-449d-96fd-b26e28361f81 MEDIUM 6.4 The Easy Menu Manager | WPZest plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in… wordfence
← Prev 489 490 491 492 493 494 495 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top