πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 504 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
eb68f3b4-b4c7-4e16-bed2-2bd41f1b5a44
< 1.9.7
MEDIUM 6.4 The WP Video Lightbox for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions… wordfence
eb689760-837f-45e6-ba51-a834053be6ae
< 2.7
MEDIUM 6.4 The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `chart_size` attribute of th… wordfence
eb5a85ba-9545-4d64-ac7c-6b856e4ab354
< 1.6.4
MEDIUM 6.4 The Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
eb4b1871-7c13-4f7c-93b5-d5254f89da8f
< 2.2.22
MEDIUM 6.4 The GeoDirectory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versio… wordfence
eb2918c4-b9b5-4cc3-a4fa-625944984a20
< 1.0.9
MEDIUM 6.4 The Dracula Dark Mode – Enhanced Accessibility, Dark Mode & Reading Mode for WordPress plugin for WordPress is vulner… wordfence
eb2776d8-1e2f-46fb-9d3b-693c8fa115b3
< 1.2.14
MEDIUM 6.4 The Pre-Orders for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortc… wordfence
eb14f2ed-6ae8-409e-86fc-c305a56f5d5b
< 1.3.3
MEDIUM 6.4 The Valuation Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜link’ parameter … wordfence
eb117172-c853-4448-9648-367bb9a0d2c2
< 1.8.1
MEDIUM 6.4 The Custom User Profile Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortc… wordfence
eb0fb0a7-b9f7-42db-b826-fc09090bd817
< 3.1.7
MEDIUM 6.4 The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross… wordfence
eaea07ad-e6f1-4f23-a508-94203967af7f
< 3.7.31
MEDIUM 6.4 WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements. wordfence
eae1c878-3df9-47af-8283-de3d5acb219a MEDIUM 6.4 The 3D Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'des[]' parameter in all … wordfence
eae0783a-a409-4947-b837-aee219b4d445
< 3.9.2
MEDIUM 6.4 The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Hero … wordfence
ead108c4-ac09-42ea-95c5-e95dc514f1cb
< 1.7.1037
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['fi… wordfence
eabdd744-1a72-40f2-b569-f56a1b913273
< 3.0.16
MEDIUM 6.4 The WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u… wordfence
eaa53088-c383-4315-9871-b4ceb83f5fdb MEDIUM 6.4 The Easy Author Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author_profile_picture_… wordfence
ea9eaca6-3441-4976-8556-0ce288d1a0c6
< 2.5.3
MEDIUM 6.4 The BP Profile Shortcodes Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
ea6e0856-ba3d-4fa1-ac90-45a51ff994ef MEDIUM 6.4 The Buttons Shortcode and Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shor… wordfence
ea630be6-16f8-4d93-ae27-8a29f82c5db9
< 1.6.0
MEDIUM 6.4 The Ultimate Store Kit Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
ea5dfd45-4f61-47e2-9b99-862921229508 MEDIUM 6.4 The Master Paper Collapse Toggle plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
ea53976d-fd64-4e23-b311-d8e462badc1e MEDIUM 6.4 The EndomondoWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.1.… wordfence
ea52bacf-e21d-4ea9-b51b-ee0c37620bf9 MEDIUM 6.4 The Magee Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in … wordfence
ea46b390-f9df-4f07-8af5-abf2b87b5fc7
< 3.30.0
MEDIUM 6.4 The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
ea41d391-ba8d-43d9-8eda-69ac28c49328 MEDIUM 6.4 The Power Charts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [p… wordfence
ea3daad1-74a1-44be-b7ed-b58b806da614
< 3.10.5
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Page Title HTML… wordfence
ea3afa3c-9a88-4f91-a74a-04306639feb5
< 5.0.0
MEDIUM 6.4 The Google Language Translator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
← Prev 501 502 503 504 505 506 507 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top