🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 500 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ef21fae3-65ef-43e8-9792-619dfc4dfda8
< 3.1.4
MEDIUM 6.4 The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sharing block in a… wordfence
ef1ccef8-9066-4f5c-b5c5-9fa6e54f0e87
< 3.1.11
MEDIUM 6.4 The Follow Us Badges plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsite_follow_us… wordfence
ef01f05a-ed5a-4278-acab-029c58242cf2
< 1.1.2
MEDIUM 6.4 The BWL Advanced FAQ Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'baf_sbox' s… wordfence
eee849d5-7698-41c5-b90d-47cc67551afd
< 1.4.6
MEDIUM 6.4 The Sided plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.5 due … wordfence
eee7cad6-7910-4860-add9-c500d1f6eff3
< 5.9.27
MEDIUM 6.4 The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
eee517de-a47e-47c9-8322-92ce772191b0
< 2.9.13
MEDIUM 6.4 The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'navigation_dots' param… wordfence
eee04b1d-188a-4b92-a6f3-dfa843ca20d7
< 3.5.4
MEDIUM 6.4 The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem… wordfence
eedced7b-bda4-4292-8e87-fc3e37e4868b
< 1.0.5
MEDIUM 6.4 The GamiPress – Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes i… wordfence
eed667d2-e53e-47b9-8012-2b9b46022f3a
< 4.8.9
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_price_lis… wordfence
eed5b1ea-213c-4a37-b357-8d058af86d38
< 1.9.4
MEDIUM 6.4 The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's … wordfence
eebe37bf-2983-47c0-afd8-0aa3e7982196
< 2.7.2
MEDIUM 6.4 The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cros… wordfence
eebc0318-8db3-44b4-ac04-d246db3a10ed
< 3.3
MEDIUM 6.4 Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark's … wordfence
eebac297-9652-4640-935e-4984280ea5fa
< 3.0
MEDIUM 6.4 The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program. plugin for WordPre… wordfence
eeae2042-ccad-4e4b-a321-8ea58af9d775
< 1.7.6
MEDIUM 6.4 The WooCommerce – Store Exporter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'export_fi… wordfence
eeabdaae-dc77-4909-9b96-b480ccaa58fb
< 2.4.15
MEDIUM 6.4 The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
eea79152-76ef-4331-8999-e13f92cd08f4 MEDIUM 6.4 The BuddyHolis TableSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ p… wordfence
ee992216-53dd-441e-9c8f-55fbe7567cb7
< 1.0.2
MEDIUM 6.4 The Video Player for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
ee96d8c5-baf0-4c5c-9ace-e88bbb95ee0a
< 1.7.1057
MEDIUM 6.4 The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed … wordfence
ee8e0751-2a9c-4822-b415-a8c6bb433ff6 MEDIUM 6.4 The Moka Get Posts Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
ee84c720-7997-4c09-a2f9-5e1a28bd1100
< 2.7.8
MEDIUM 6.4 The Countdown Timer – Widget Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
ee725cff-959d-4078-9c2e-2d52bb904ca0
< 1.2.0
MEDIUM 6.4 The Allow SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up t… wordfence
ee6b1497-ffac-4eb3-baad-36270e419a95
< 8.1.0
MEDIUM 6.4 The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-… wordfence
ee396f94-8934-47db-9bc8-783a2b20f427
< 1.5.33
MEDIUM 6.4 The Breadcrumb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'breadcrumb_themes' (within in the … wordfence
ee2455fb-69b9-4dbc-9c59-fd2cdd5b4d0f
< 12.2.8
MEDIUM 6.4 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
ee1c9c62-d5b5-4213-ae5a-d3d4e9103d15
< 2.2.3
MEDIUM 6.4 The 3DVieweronline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '3Dvo-model' short… wordfence
← Prev 497 498 499 500 501 502 503 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top