πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 493 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f5dc94fc-de11-42e7-a598-956ad345e7ff
< 2.1.0
MEDIUM 6.4 The Zoho Campaigns plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
f5d43612-ae16-4fa4-a1f0-91540ebac264 MEDIUM 6.4 The LiveJournal Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lj' shortc… wordfence
f5bfe0a1-bc18-46d2-8358-5c3e1e883157
< 2.2.9.2
MEDIUM 6.4 The JetTabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.9.1 … wordfence
f5bdf47a-1116-4d3a-8ded-89d76b5a6f82
< 1.0.2
MEDIUM 6.4 The User Notes plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including 1.0.1, due to… wordfence
f5afe6ea-93b8-4782-8593-76468e370a45
< 2.1.10
MEDIUM 6.4 The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
f5ace7fb-530e-4a69-bbf7-e2c66491dd75
< 1.6.9.1
MEDIUM 6.4 The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vul… wordfence
f5ac3714-27f1-4258-a1ab-12b969b31793 MEDIUM 6.4 The Layer Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1… wordfence
f5ab7d3e-b0c8-4e30-942b-23d91daff2ac
< 2.1.0
MEDIUM 6.4 The Secondary Title plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
f5a4a017-52d7-44a5-b00f-ce13eda989bc
< 9.8.0
MEDIUM 6.4 The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media Image U… wordfence
f5a37df3-001b-4acd-91b1-7961896fb71f
< 1.60
MEDIUM 6.4 The Mortgage Calculators WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and… wordfence
f592a397-5de5-431a-b680-1262b521f32d
< 4.0.0
MEDIUM 6.4 The NGG Smart Image Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
f584a439-3373-441c-a73e-5931ae63e7ae
< 4.0.1
MEDIUM 6.4 The Simple Contact Form Plugin for WordPress – WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
f56259cf-7d3a-441d-9078-372b84e9ff7f MEDIUM 6.4 The Boo Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.… wordfence
f5608f50-e17a-471f-b644-dceb64d82f0c
< 3.0.0
MEDIUM 6.4 The Ziteboard Online Whiteboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ziteboard' sh… wordfence
f55e0471-664c-4fb4-8776-0c8312d8327b
< 4.0.3
MEDIUM 6.4 The MainWP Code Snippets Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and inc… wordfence
f55c004a-366b-4555-9b3c-e2172a2e7f56
< 7.1.8
MEDIUM 6.4 The Stylish Price List – Price Table Builder & QR Code Restaurant Menu plugin for WordPress is vulnerable to Stored Cr… wordfence
f5373990-27a8-4e6e-a392-1c86bd76511d
< 4.2.23
MEDIUM 6.4 The MultiVendorX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2… wordfence
f535777b-eae3-4ea7-86f2-b6edfe9ad5ab
< 3.0.4
MEDIUM 6.4 The Upcasted S3 Offload – AWS S3, Digital Ocean Spaces, Backblaze, Minio and more plugin for WordPress is vulnerable t… wordfence
f531489b-a87d-41e7-a988-8b29840047ec
< 1.6.1
MEDIUM 6.4 The GS Filterable Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode… wordfence
f5292c55-6445-4aec-b06e-6e625794d842
< 3.17.2
MEDIUM 6.4 The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross Site Scripting in ver… wordfence
f528e0bd-ab4b-4d0b-b133-90bd1312479f
< 7.43
MEDIUM 6.4 The WP Custom Admin Interface plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
f51d50c8-249d-423e-ac2f-1f0939ec8ba1
< 3.3.1
MEDIUM 6.4 The Wishlist for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
f5184598-b0bd-4026-971c-da36d79497df
< 4.7.5
MEDIUM 6.4 The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored C… wordfence
f4fbf8d5-dae6-4db4-b4c3-7b2254983813 MEDIUM 6.4 The Post Signature plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0… wordfence
f4f52cb6-eccf-4213-ae44-4a3fa738723d
< 1.0.23
MEDIUM 6.4 The Property Hive Stamp Duty Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… wordfence
← Prev 490 491 492 493 494 495 496 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top