πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 505 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ea39d249-0345-4028-af58-31b298376950 MEDIUM 6.4 The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribu… wordfence
ea251110-02fa-4f4e-a578-855d3331b200
< 1.2.3
MEDIUM 6.4 The B Testimonial – testimonial plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
ea23bcc2-ce71-4f16-85f3-11276deb659f
< 1.8.5.6
MEDIUM 6.4 The Collapse-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'expand' shortco… wordfence
ea174c08-4601-4f40-a6d0-a4fc95bf71e9
< 1.4.3
MEDIUM 6.4 The Conversational Forms for ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
e9fea7e4-00d8-4f8b-9ee8-8e0deb179141 MEDIUM 6.4 The Penci Recipe plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1… wordfence
e9fc118e-f402-4042-85b0-2175cb0e3048
< 1.0.70
MEDIUM 6.4 The 10Web Map Builder for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜&map_… wordfence
e9f2e84a-f640-49b1-b01a-068c922dcc57
< 3.4.2
MEDIUM 6.4 The WBC907 Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.… wordfence
e9e49406-a007-4c38-8e69-bf4b5438260e
< 4.4.3
MEDIUM 6.4 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
e9e30377-2b5a-4b2d-9f19-bae91608fb24
< 1.73.8
MEDIUM 6.4 The Memberful – Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '… wordfence
e9d42cc5-c213-454b-b05a-a57705e5c7e4
< 2.5.1
MEDIUM 6.4 The Plugins List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the replace_plugin_list_tags func… wordfence
e9bbfa58-1f39-4d38-bdbd-9dae754bfb7a MEDIUM 6.4 The Leyka plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.31.9 due… wordfence
e9b58db6-4059-4923-b1e3-3321cc7d3573
< 7.4.2
MEDIUM 6.4 The Avada plugin for WordPress is vulnerable to Stored Cross-Site Scripting via improper escaping of HTML form entries i… wordfence
e9b28209-498f-4319-be87-3f54c64d9ccd
< 1.5.0
MEDIUM 6.4 The 'CM Pop-Up banners' plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
e9ad2dff-0c6d-4d91-a35d-803b97def01f
< 2.6.9.3
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜exad_inf… wordfence
e9ab836b-2798-43bd-b43b-8b7c7e81d42f
< 3.3.7
MEDIUM 6.4 The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
e9a89613-cfd9-4a96-b8eb-4b17376be433
< 2.0.8
MEDIUM 6.4 The WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce plugin for Word… wordfence
e9a0ca58-ddc1-43ec-bb08-7fd31f92e275
< 2.0.11
MEDIUM 6.4 The PropertyHive plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0… wordfence
e997974c-733c-4c98-9de5-876681194bdd MEDIUM 6.4 The Navigation Du Lapin Blanc plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
e9946828-7241-445f-b1be-b05864b80ec2 MEDIUM 6.4 The Clink plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.2 due … wordfence
e9944443-2e71-45c4-8a19-d76863cf66df
< 2023.9
MEDIUM 6.4 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcod… wordfence
e993667f-8275-4078-afd5-b26ff8528ab4 MEDIUM 6.4 The Simple Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.6… wordfence
e9914ecb-0214-4991-96ae-425da7104ede
< 2.2.1
MEDIUM 6.4 The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
e97854ca-b24f-4893-862d-f8e975752175
< 1.6.28
MEDIUM 6.4 The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API entry submission endpoint… wordfence
e96d118a-e38c-4043-9550-5f5ab0d83dc7 MEDIUM 6.4 The FastSpring plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fastspring/block-fast… wordfence
e93de7ae-c3a8-4536-9c07-e64d7746e05f
< 2.2.12
MEDIUM 6.4 The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPre… wordfence
← Prev 502 503 504 505 506 507 508 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top