🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 498 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f090e1f1-2713-4f3a-b908-9407c242fdf9
< 2.1.9
MEDIUM 6.4 The Gutenberge Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in… wordfence
f08ca5e3-8b48-4333-9c42-cc103d40394c
< 2.0.54
MEDIUM 6.4 The Related Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all … wordfence
f0869c35-9ea8-46a5-8bba-23d7ef47355a
< 7.3.4
MEDIUM 6.4 The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
f07eb033-f84b-4a17-9b8c-c767ae9285ae MEDIUM 6.4 The SEO Friendly Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
f07d22ef-5afd-48a4-9e67-31a3ab3efdd6
< 0.11
MEDIUM 6.4 The Personizely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘widgetId’ parameter in al… wordfence
f07881db-7494-4e6d-82ea-16018fa81806
< 2.0
MEDIUM 6.4 The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter… wordfence
f06e9b82-0a5e-4907-8e0e-f10769b02cda
< 2.2.5
MEDIUM 6.4 The WPAdverts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.4 … wordfence
f05b82c3-bb29-494e-a020-427cb1a816a0
< 1.7.7
MEDIUM 6.4 A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitatio… wordfence
f0533fca-a4de-44f0-bea0-1df6a41709ca
< 7.4.4
MEDIUM 6.4 The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu… wordfence
f0490b1a-5467-4ce2-ab26-04dade3ec352
< 1.0.1
MEDIUM 6.4 The Show/Hide Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
f033b843-d26a-4176-badd-3d0e2c2aa30f
< 1.3.1
MEDIUM 6.4 The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3 du… wordfence
f027626a-471c-48aa-add6-7597254dcfa9 MEDIUM 6.4 The WP SoundSystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsstm-track short… wordfence
f0257620-3a0e-4011-9378-7aa423e7c0b2
< 7.1.3
MEDIUM 6.4 The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcj_image' shortcode … wordfence
f0174718-cddb-4821-b71e-ca21eb913842
< 2.0.23
MEDIUM 6.4 The My Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.2… wordfence
f00ef5c1-1025-489c-a294-a87e10afde2b
< 5.17.0
MEDIUM 6.4 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via either a ‘c… wordfence
eff83c19-c223-4f70-affc-adb0f560264a MEDIUM 6.4 The Uploading SVG, WEBP and ICO files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG images i… wordfence
eff765b4-22d1-4311-8a69-af6b41ef4b6e
< 3.15.19
MEDIUM 6.4 The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress i… wordfence
efe832cc-d097-41e4-a856-16f19a735358 MEDIUM 6.4 The Simple Plyr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'poster' parameter in the 'ply… wordfence
efe6d975-310d-4286-af2a-e599990e3b0b
< 1.0.0.11
MEDIUM 6.4 The Web Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versio… wordfence
efdeca40-e021-478f-af75-c5566ae70735
< 5.3.0
MEDIUM 6.4 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Store… wordfence
efdb6ec5-e6a8-4279-b637-38267a852472 MEDIUM 6.4 The Survey Anyplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'surveyanyplace_e… wordfence
efd81ba5-b9e6-493a-a6a4-55c9e2971378
< 1.0.8
MEDIUM 6.4 The corner-ad plugin before 1.0.8 for WordPress has XSS. wordfence
efd5ce76-2f93-45f9-9822-b0f8b6fcff0b MEDIUM 6.4 The Enhanced BibliPlug plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bibliplug_aut… wordfence
efd49905-0f2c-44b7-85c6-c2b77440ac17
< 0.2.5
MEDIUM 6.4 The Ganohrs Toggle Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggle'… wordfence
efc2e391-c8d1-48c7-af53-ff6b91373325 MEDIUM 6.4 The Whitish Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.… wordfence
← Prev 495 496 497 498 499 500 501 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top