πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 499 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
efc2baf0-38d9-44be-b439-3585b2f1d4a5
< 1.1.27
MEDIUM 6.4 The CubeWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cubewp_shortcode_taxonomy … wordfence
efbdf0f0-6b38-418c-b3fb-396f89ada34f
< 2.7.11
MEDIUM 6.4 The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cros… wordfence
efbcac1c-854c-4521-848a-d403bc27328f MEDIUM 6.4 The Flexible Captcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in ve… wordfence
efbbb33d-28ed-47f4-a8dd-2fc7564d9df2 MEDIUM 6.4 The RightMessage WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rm_area' shortco… wordfence
efb816e4-c07f-4e72-bfd3-06d83ed4d642
< 2.9.2
MEDIUM 6.4 The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
efb692da-6878-420a-b16e-2cb871bef764
< 1.7.13
MEDIUM 6.4 The PDF Flipbook, 3D Flipbook WordPress – DearFlip WordPress plugin before 1.7.13 does not escape the class attribute … wordfence
efb1c2fa-0f8b-4221-ba13-3b94319b3c89 MEDIUM 6.4 The News Articles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
efb0c7d9-0e93-404b-9032-54d64cfcd4c3
< 1.6.12
MEDIUM 6.4 The Fullscreen Galleria plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
efacb174-5eb6-4a58-bd76-8111031bbd4d
< 5.5
MEDIUM 6.4 The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and i… wordfence
efac70f6-d959-41f7-bdef-d554f1c9133e
< 4.25.1
MEDIUM 6.4 The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Store… wordfence
efa156b7-ab18-414d-80a5-3a1c2a977b3b
< 2.0.2
MEDIUM 6.4 The Themify Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all… wordfence
ef93491a-5965-4289-b72c-d1568ff4e6e8
< 6.4.2
MEDIUM 6.4 The Recras WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'recrasname' shortcode at… wordfence
ef8fca84-3ea1-432f-8cfe-9a1d1f70fa6f
< 3.29
MEDIUM 6.4 The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aws_search_te… wordfence
ef8697a2-7c58-43be-aaa9-05273fc3114b
< 3.0.33
MEDIUM 6.4 The Ditty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up… wordfence
ef847b12-a380-410a-9368-6b2751d1836e
< 1.13.7
MEDIUM 6.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
ef7b80c4-09b8-443a-8d69-b33511f8cf18 MEDIUM 6.4 The Send E-mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3 … wordfence
ef792894-b841-495c-aae0-08476a435471
< 9.0.37
MEDIUM 6.4 The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
ef6ce2ef-f810-4f8c-a0bd-785a28131213 MEDIUM 6.4 The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute … wordfence
ef6b80c1-7f5e-4f8d-964a-a9c9c4f2a882
< 2.0.4
MEDIUM 6.4 The Genesis Columns Advanced plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod… wordfence
ef5bccca-39d6-40e2-94fa-b321da58789d
< 1.5.2
MEDIUM 6.4 The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Offered Salary', '… wordfence
ef4ecdd3-1041-4dbe-a804-59a51f6123e4
< 1.1.9
MEDIUM 6.4 The Videojs HTML5 Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes (such as 'url'… wordfence
ef4603b2-bd41-4f65-ba2a-8d06e32e67c1 MEDIUM 6.4 The Testimonials Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonials … wordfence
ef395956-477c-4970-becd-4f437e4807a3
< 2.1.13
MEDIUM 6.4 The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' short… wordfence
ef36a2a1-b3be-4270-8890-76705817b4b5 MEDIUM 6.4 The WP Custom Fields Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcfs-pre… wordfence
ef2c89d1-7cc4-4efa-841a-7edb98d874c1
< 4.0.3
MEDIUM 6.4 The Logo Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… wordfence
← Prev 496 497 498 499 500 501 502 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top