🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 502 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ed686f11-e696-415c-92cf-55fb789191a1 MEDIUM 6.4 The MakeStories (for Google Web Stories) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio… wordfence
ed684438-323e-4cf1-b4f1-955b1da63ad8 MEDIUM 6.4 The Kento Ads Rotator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
ed56e702-0a3c-47aa-bac0-0ec5afc1034e MEDIUM 6.4 The Курс валют UAH plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
ed357f21-bc35-4a9b-983e-1eb836aa4049
< 4.11.1
MEDIUM 6.4 The JupiterX Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… wordfence
ed228515-04de-49b7-a103-355887cb7318
< 3.1.1-free
MEDIUM 6.4 The FireBox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.0-fr… wordfence
ed1a7872-e268-460d-82f1-b047335a9977 MEDIUM 6.4 The hk_shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title-plane' shortcode in ve… wordfence
ed191380-6037-4d59-8db7-cb33136a304e
< 1.3.7
MEDIUM 6.4 The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
ed15cb66-c386-45af-9a79-e187c4be38a8
< 3.0.2
MEDIUM 6.4 The SpendeOnline.org plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spendeonline' s… wordfence
ed137706-1313-4bff-882b-13d9fa11498c MEDIUM 6.4 The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
ed0e7717-d9ac-4333-8e79-fc030a410dab
< 2.1.0
MEDIUM 6.4 The CC BMI Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu… wordfence
ecfe9e4c-baa8-44ae-8784-3d14faf3fe91
< 1.4.20
MEDIUM 6.4 The Modern Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
ecfc1466-41d2-498b-8210-c67e8550f5b8
< 1.13.6
MEDIUM 6.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ and 'eae… wordfence
ecf476a8-e341-44d4-988c-a7fb3fb538d1
< 2.8.19
MEDIUM 6.4 The Stockdio Historical Chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stockd… wordfence
eceef5c6-ab17-405a-838f-4259072c5280
< 1.4.0
MEDIUM 6.4 The Event Feed for Eventbrite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
ecebc618-2d39-4284-bb31-59de0e17bc63 MEDIUM 6.4 The Footnotes for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
ecd8a81b-b1db-411b-90f4-2a7de3a3ca27
< 1.2.5
MEDIUM 6.4 The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
ecd4ed5d-333c-40c1-a241-683b657ba417
< 1.8.0.3
MEDIUM 6.4 The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
ecd01ea6-9476-47e1-9959-3f8d9ce1c1f3
< 3.20.2
MEDIUM 6.4 The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an SVGZ file upl… wordfence
eccaf0cc-4626-40db-942b-7e939be1a8fa
< 2.0.15.1
MEDIUM 6.4 The JetPopup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.15 … wordfence
eccad28f-f55f-4c7e-a163-3b2015e7e50b
< 1.2.2
MEDIUM 6.4 The HT Conctact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
ecc5a17e-c716-48bd-9b4d-49d870ae6bf3
< 2.10.28
MEDIUM 6.4 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Ta… wordfence
ecc55a5b-efb4-45a3-9764-f297a6bcfb69
< 2.3.15
MEDIUM 6.4 The Firelight Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via posts in all versions up to… wordfence
ecae113c-c66a-4f27-bf81-6679a4717ff8
< 3.4.6
MEDIUM 6.4 The affiliate-toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various ratings postmeta par… wordfence
ecad5438-8992-454c-bdc8-fac7635c1024
< 3.5.9
MEDIUM 6.4 The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via blocks in versions up to, and inclu… wordfence
ec9d3cca-7061-4dc4-9c71-b2ffbfde120b
< 1.7.0
MEDIUM 6.4 The Structured Content (JSON-LD) #wpsc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ blo… wordfence
← Prev 499 500 501 502 503 504 505 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top