πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 503 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ec93f360-2eed-4858-b36f-8cc17f7b4ac1 MEDIUM 6.4 The Remote Content Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an… wordfence
ec882062-0059-47ca-a007-3347e7adb70b
< 3.1.4
MEDIUM 6.4 The WP Mailto Links – Protect Email Addresses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'w… wordfence
ec857762-9506-4df0-afe6-7f738df976a2
< 2.0.10
MEDIUM 6.4 The Get Use APIs – JSON Content Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… wordfence
ec7649da-5358-4fe2-8706-b945bba02c93
< 7.1.7
MEDIUM 6.4 The WP Shortcodes Plugin β€” Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
ec5fc038-b855-4744-8797-ce2cedd88f6a MEDIUM 6.4 The Bitcoin Satoshi Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via one of its AJAX calls in… wordfence
ec5474ac-62d7-4431-b789-51c831dd1c20 MEDIUM 6.4 The Flat UI Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's flatbtn shortcode … wordfence
ec4d27d6-b54f-4fac-9a49-6798da4f0acc
< 1.60.213
MEDIUM 6.4 The WP Fast Total Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the WPFTS Live Search wid… wordfence
ec49ed83-a09d-460d-be34-0fb79032b543 MEDIUM 6.4 The WP-Clippy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `clippy` shortcode in a… wordfence
ec47ffee-0599-4f16-a71d-d17dcfe9b183
< 2.6.1
MEDIUM 6.4 The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $search_label parame… wordfence
ec41956f-eefc-4c8b-ade1-2a3a0f3d86df
< 2.7.9.2
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML attrib… wordfence
ec3de7e2-4a29-401f-af2c-0ce78d768eae
< 4.3.2
MEDIUM 6.4 The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cr… wordfence
ec33a828-6387-42d3-b0ab-a2461ff1a4c4
< 1.7.1065
MEDIUM 6.4 The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
ec2f2856-fd13-48cb-b335-a66c8cb35b6b MEDIUM 6.4 The Spiderpowa Embed PDF plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
ec201702-8c8c-4049-b647-422d18001b7f
< 9.1.1
MEDIUM 6.4 The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in a… wordfence
ec1ffc70-fc0c-4c25-926c-e78e0f206d2b
< 1.1.6
MEDIUM 6.4 The Simple Posts Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) … wordfence
ec1f4180-6fa0-418b-8387-553890cfed0a
< 1.1.4
MEDIUM 6.4 The All Embed – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
ebf96aa9-2ee7-4411-8f43-3e8d023197bd
< 3.3.61
MEDIUM 6.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attri… wordfence
ebf1e74c-4199-4de1-aa4c-05d0d208d759
< 3.3.2
MEDIUM 6.4 The Categories Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
ebe03cde-7956-4185-8990-8d47f174e60a
< 2.1.8
MEDIUM 6.4 The WP Calameo plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.7… wordfence
ebcce8ab-b1c9-49ce-986d-c6d0e5672dec MEDIUM 6.4 The Surbma | Yoast SEO Breadcrumb Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
ebb275e9-3a5b-421e-b857-95880ebe000d
< 2.5.1
MEDIUM 6.4 The JobCareer theme before 2.5.1 for WordPress has stored XSS. wordfence
ebad8cb0-ac50-414e-9e13-7741da6915e7
< 2.4.3
MEDIUM 6.4 The GutenKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.2 d… wordfence
ebad60ee-8596-46c8-9461-9caf6c6a3454
< 2.0.2
MEDIUM 6.4 The CBX Map for Google Map & OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pop… wordfence
eb9bcd3e-bb8c-4c7b-8904-56790acd2655
< 3.4
MEDIUM 6.4 The WP Google My Business Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'… wordfence
eb6f38ce-2378-480f-8f43-140ed7be5cc0
< 2.3.7
MEDIUM 6.4 The PixCodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions u… wordfence
← Prev 500 501 502 503 504 505 506 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top