🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 501 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ee18552b-2814-4598-9b7b-7c919d6d644e
< 4.16.2
MEDIUM 6.4 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
ee10221e-ce76-4c20-abc7-26ace2f4e619
< 2.5.0
MEDIUM 6.4 The Free Shipping Bar: Amount Left for Free Shipping for WooCommerce plugin for WordPress is vulnerable to Stored Cross-… wordfence
ee0acdaa-3c56-4a57-865e-44e8ecd7fba0
< 4.5.0
MEDIUM 6.4 The SpeakOut! Email Petitions plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
ee069cb3-370e-48ea-aa35-c30fe83c2498
< 4.8.1
MEDIUM 6.4 The Oxygen Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom field in all versions … wordfence
ee03d780-076b-4501-a353-376198a4bd7b
< 7.0.3
MEDIUM 6.4 The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
ee031b29-a334-4df4-8c03-4ffd306e38ea
< 1.9.2
MEDIUM 6.4 The Campus Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parame… wordfence
edf62f82-448a-4ed8-8d4b-7215223494cb
< 6.2.0
MEDIUM 6.4 The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordP… wordfence
edecb27b-ff11-4186-b8a8-41a85e3e2023
< 2.0.40
MEDIUM 6.4 The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘currency_code’… wordfence
edd24cfd-723d-4dc4-a301-43f858dcd7f3
< 6.8.1
MEDIUM 6.4 The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fusedesk_newcase shortco… wordfence
edc4f76e-9f0e-4f36-becb-fcb489c66e41 MEDIUM 6.4 The Black Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
edc4875e-3eca-4c25-a65c-93182912cd24 MEDIUM 6.4 The WordPress Live Webcam Widget & Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p… wordfence
edbdb4d4-b648-4bf1-9ddc-b89f91c927e8
< 1.6
MEDIUM 6.4 The Simple Google Photos Grid plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a… wordfence
edb82ef3-fb58-45db-9c29-1589a160a0c6
< 1.2.0
MEDIUM 6.4 The Print PDF Generator and Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
edb72f0c-9651-4319-b5f6-84ca052c6ade
< 2.0.11
MEDIUM 6.4 The Search with Typesense plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
edb62de4-2d98-46fa-9244-585a547c0d27
< 2.0
MEDIUM 6.4 The Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
edb4f4b7-a59c-454b-82b5-d8e91c1c82a3
< 1.3.0
MEDIUM 6.4 The ARI Stream Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
edb34cf0-cbd7-412d-9ac3-2e065c7f32ab
< 1.1.9
MEDIUM 6.4 The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
edae5471-57b4-4bac-9cef-90019b40345a MEDIUM 6.4 The AMP Img Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
ed9f8948-085b-4ac5-befd-c70085aa23cd
< 3.7
MEDIUM 6.4 The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Scripting in version… wordfence
ed98d335-16f9-4be8-bace-06e2b5db4cb9
< 1.04
MEDIUM 6.4 The Simple Share Follow Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortc… wordfence
ed918a4b-2423-4ac2-882c-f2970b960d71
< 1.7.7
MEDIUM 6.4 The Fusion Page Builder : Extension - Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
ed914e67-4cf7-49b1-96be-ed8c604e6dce
< 4.6.9
MEDIUM 6.4 The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up … wordfence
ed86e902-7637-481d-9005-7025187ba200
< 1.7.1059
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titl… wordfence
ed8408b0-b14c-4f01-abdd-e7019dd985b4
< 4.3.0
MEDIUM 6.4 The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.9… wordfence
ed6d1167-c89d-4c97-9446-b968df945e6c MEDIUM 6.4 The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute … wordfence
← Prev 498 499 500 501 502 503 504 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top