🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 497 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f153a0ce-c967-43ed-97be-901ea7dcd12b MEDIUM 6.4 The Custom Word Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘angle’ parameter in… wordfence
f153174a-1226-4c16-ba8b-637be1d7e742
< 1.0.5
MEDIUM 6.4 The WPRadio – WordPress Radio Streaming Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
f147641a-f430-4743-901e-539373dc10b7
< 1.11.30
MEDIUM 6.4 The Memberpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘arglist’ parameter in all… wordfence
f138d917-0dc2-4408-aa6a-db1fd0410eb4
< 5.0.2
MEDIUM 6.4 The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
f1275a8f-c9ac-4cb3-8aa2-1393ffcc9dc8 MEDIUM 6.4 The VigLink SpotLight By ShortCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'float' par… wordfence
f1205432-4de0-4745-b8d5-e36aa8f3da49 MEDIUM 6.4 The Common Ninja: Fully Customizable & Perfectly Responsive Free Widgets for WordPress Websites plugin for WordPress is … wordfence
f11ea6b2-1225-42a5-aa7b-260315d0bec5
< 2.0.6
MEDIUM 6.4 The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions… wordfence
f11bc707-2465-4b64-945a-c0db6e9043dd
< 3.22.2
MEDIUM 6.4 The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to arbitrary SVG file… wordfence
f117f713-e2f1-4803-87f7-14b1576d823b
< 1.6.0
MEDIUM 6.4 The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `lightweigh… wordfence
f0ff03ab-eeb9-4445-92c8-326783d4b10e
< 2.1.3
MEDIUM 6.4 The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in several widgets… wordfence
f0fd9a70-f725-440b-8d39-af99e4b2f3ff
< 1.1.0
MEDIUM 6.4 The Cresta Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
f0f78d20-7739-4c6f-9f1b-c94e3de4df4d MEDIUM 6.4 The BlockWheels plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.… wordfence
f0eb6dc5-98e2-4d88-98f8-8a63c939b047
< 2.1.7
MEDIUM 6.4 The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User'… wordfence
f0e7433a-48a8-4601-a242-9923c6014394
< 4.2.19
MEDIUM 6.4 The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.18 … wordfence
f0dc7356-0b15-4dd8-b335-9e0274d1cc59
< 2.6.2
MEDIUM 6.4 The Content Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
f0d3b54c-6244-4776-be3c-afe3a28a2b8a
< 1.2.2
MEDIUM 6.4 The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_title' parameter … wordfence
f0d0eaa0-ad8f-418c-bb61-eb209ba0249b MEDIUM 6.4 The Coon Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in the… wordfence
f0ccd265-2e64-4b23-a032-aaeb9941df34
< 2023.10.21
MEDIUM 6.4 The Daily Prayer Time plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in… wordfence
f0cc349a-96f9-4b11-a0b4-28bc4ccc022c MEDIUM 6.4 The Auto Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'thumbnails' shortcode in a… wordfence
f0b8fd44-75af-4fb8-bcc1-94cb5fc9e4eb
< 1.7
MEDIUM 6.4 The GDPR Data Request Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form_id parameter … wordfence
f0b12d5d-5b13-4eb0-ad48-2b7c431703bd
< 3.9
MEDIUM 6.4 The Simple HTML Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
f0a3df32-aa07-4cc0-97ba-bb4ab64ba6b9 MEDIUM 6.4 The Include Fussball.de Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api' and 'typ… wordfence
f0a21eaa-4e2a-4d07-8635-f0a8a5db660f
< 3.12.2
MEDIUM 6.4 The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusion_ma… wordfence
f09ffc02-bfed-4aa3-a3d3-58e188b3e147
< 4.2.0
MEDIUM 6.4 The Event RSVP and Simple Event Management Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
f098e597-6938-48c8-948c-94cb475b8f6c
< 1.7.5
MEDIUM 6.4 The Dynamic Conditions plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
← Prev 494 495 496 497 498 499 500 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top