🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 495 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f3ef0c46-5765-458e-80c0-ecfc6ead6df6 MEDIUM 6.4 The Ultimate WP Query Search Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's s… wordfence
f3e74fb9-edb5-4602-9aac-375701a82f84
< 3.6.4
MEDIUM 6.4 The Better WP Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘license’ parameter… wordfence
f3e4118a-e860-4378-9fa0-9f49d7012cc8 MEDIUM 6.4 The ThemeShark Templates & Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… wordfence
f3e1d66d-34cf-491c-8a07-0f9efd3c9669 MEDIUM 6.4 The Post Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in ve… wordfence
f3db71e8-1a0c-47d8-babd-a84a25a8b467 MEDIUM 6.4 The ShortcodeHub plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_link_target’ para… wordfence
f3dac7b6-512d-4fd6-8294-f0b1c0a2efd7
< 3.8.1
MEDIUM 6.4 The Editorial Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wheel-support’ par… wordfence
f3b265d9-dddd-4cf7-8d1a-980fdd17777d MEDIUM 6.4 The everviz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `everviz` shortcode attributes in … wordfence
f3ae1c32-18a7-4109-a7ea-dfd18fa3a8e2
< 5.9.7
MEDIUM 6.4 The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's events_cal shortcode i… wordfence
f3945fbe-5ba0-44e3-ae1d-33a53592da1a MEDIUM 6.4 The WP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3 due … wordfence
f389f8ee-6d8f-40a8-be52-d2b26b560089
< 19.9.9.1
MEDIUM 6.4 The Rehub theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 19.9.9.1 due to insufficien… wordfence
f37fb598-72a2-48d3-b2e6-63d6654b1474
< 1.1.0
MEDIUM 6.4 The Advanced Category and Custom Taxonomy Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
f36fea15-0475-45ee-b913-790db6373aef
< 1.13.4
MEDIUM 6.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group… wordfence
f36f1ea5-62f7-48f0-a8d3-a56e0c9915d7
< 4.9.1
MEDIUM 6.4 The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File inclusion in all versi… wordfence
f36c785f-9b8c-43c4-b12f-6fb4c0c67eff
< 5.5.3
MEDIUM 6.4 The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordP… wordfence
f3559bba-daa2-4a00-958c-6568cdbb592f
< 2.5.3
MEDIUM 6.4 The Carousel, Slider, Gallery by WP Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugi… wordfence
f34904b5-3b3d-46d3-9e33-ef661d5f4149
< 1.6.0
MEDIUM 6.4 The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cro… wordfence
f348e019-d4b5-4384-8ee9-117694259b92 MEDIUM 6.4 The WP Find Your Nearest plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
f34722fb-e852-4194-b839-7d885d212fc9
< 3.8.0
MEDIUM 6.4 The Front User Submit | Front Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘formBu… wordfence
f33af49c-30b8-447f-a462-8489415c92bf MEDIUM 6.4 The Country Flags for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
f31bd18e-57d4-4c87-8a7c-a168e7e70061
< 6.0.3
MEDIUM 6.4 The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in … wordfence
f3154a7a-b8b3-490b-9822-b3a92d1b4fef
< 4.0.0
MEDIUM 6.4 The WP Ultimate Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpupg-grid-… wordfence
f314340c-23aa-479f-9a19-f21a14d6da49 MEDIUM 6.4 The Responsive WordPress Slider WordPress plugin through 2.2.0 does not sanitise and escape some of the Slider options, … wordfence
f2fb7a5f-ea09-4033-a19e-f3d0e9689cf3
< 1.8.0
MEDIUM 6.4 The Behance Portfolio Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
f2f11c32-d58e-4ac8-83c7-30927a626e10
< 1.5.113
MEDIUM 6.4 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros… wordfence
f2d7c5b6-ce4d-4dbe-abec-8c223cb652af
< 3.2.20
MEDIUM 6.4 The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Server-Side R… wordfence
← Prev 492 493 494 495 496 497 498 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top