🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 496 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f2cf46e6-a732-45c4-ad18-607009d7a586 MEDIUM 6.4 The OMIGO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `omigo_donate_button` short… wordfence
f2c56e24-ebff-4b2d-b5ad-4f25ee20f91d MEDIUM 6.4 The Getty Images plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,… wordfence
f29b3a37-436d-4d03-8818-d5267b23067b
< 4.3.2
MEDIUM 6.4 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all version… wordfence
f286e61a-1afc-4f51-8b53-f3456a20150a
< 5.114.0
MEDIUM 6.4 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Short… wordfence
f27979a8-0e68-4a45-9e3e-3667d88361d8
< 3.6.3
MEDIUM 6.4 The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘list_tag’ parameter in all … wordfence
f266f9db-a25e-4f50-b3c8-3bea3a7e86ce
< 3.6.0.1
MEDIUM 6.4 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pric… wordfence
f2667b7c-b743-44d1-90d6-b1be6fcd7dca
< 2.1.34
MEDIUM 6.4 The Premium Blocks – Gutenberg Blocks for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
f23dec73-9031-4829-a84b-4979c8e8ded4
< 2.3.1
MEDIUM 6.4 The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sdc_menu' shortco… wordfence
f23604b7-5a7f-4be7-bc73-cb4facdd1e73
< 3.25.10
MEDIUM 6.4 The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
f232f550-f964-4a69-9a80-aa9768149094
< .53.4
MEDIUM 6.4 The BulletProof Security plugin for WordPress is vulnerable to Cross-Site Scripting via the ‘user-agent-ignore’ para… wordfence
f2000a8b-85e4-4031-a24b-a6e0ced774cc MEDIUM 6.4 The Aajoda Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
f1fd67c1-fbe8-4bad-a052-a73ad1c6e75d MEDIUM 6.4 The Sitekit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0 due … wordfence
f1fca56e-ef15-4cfe-80b7-7f692e9c0c6e MEDIUM 6.4 The 金数据 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 du… wordfence
f1fa59e0-c946-40d3-a817-c9924b4588fa MEDIUM 6.4 The ZoomifyWP Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filename' parameter of the… wordfence
f1ec6957-28c0-4441-8801-80b226569df9
< 2.0.7
MEDIUM 6.4 The SweepWidget Contests, Giveaways, Photo Contests, Competitions plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
f1e40072-7426-40ff-98bb-c4d1b325937c MEDIUM 6.4 The Subscription Form for Feedblitz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
f1e1a9ab-9ba9-45ff-aecd-b8953abc653a MEDIUM 6.4 The TimeZoneCalculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'timezonecalcu… wordfence
f1dd0fa6-c6af-4a68-bc2a-c54dc40141db MEDIUM 6.4 The Fiverr.com Official Search Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
f1dcafe1-bdba-4476-bcc7-ad844da38a01
< 3.10.8
MEDIUM 6.4 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
f1c68f9d-a026-4cef-82e6-25949a3d59ad MEDIUM 6.4 The GutenGeek Free Gutenberg Blocks for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
f1bf4f77-9539-4a9f-afec-f43f602c684f
< 6.9.19
MEDIUM 6.4 The Advanced Access Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode… wordfence
f19c84c7-9b27-48b0-b648-b5681eff1371
< 1.1.13
MEDIUM 6.4 The Advanced Custom Fields: Table Field plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions be… wordfence
f1939a30-50eb-4ad6-98e7-f94afade3efa
< 1.10
MEDIUM 6.4 The WP Flipclock plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9… wordfence
f188337e-023e-498e-b752-b5f3fa7a9949
< 1.2.1
MEDIUM 6.4 The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of th… wordfence
f15f0211-724d-45b5-bf2f-7482f77c474d MEDIUM 6.4 The Wonka Slide plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `list_class` shortcod… wordfence
← Prev 493 494 495 496 497 498 499 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top