🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 506 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e9346103-9773-4cda-9b32-d3ce2076e8fb
< 1.2.2
MEDIUM 6.4 The Advanced Floating Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters i… wordfence
e933b71b-5212-4930-94ef-b4bbe8250bad MEDIUM 6.4 The Metadata SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3… wordfence
e93060cf-2df3-4d45-a1f2-304f443d58bc
< 1.0.18
MEDIUM 6.4 The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` … wordfence
e92a0387-bd09-46d3-9f6c-09f701b9e550
< 1.7.1
MEDIUM 6.4 The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom postmeta output… wordfence
e90f04e4-eb4c-4822-89c6-79f553987c37
< 2.1.9
MEDIUM 6.4 The Email Encoder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eeb_mailto' shortcode in ve… wordfence
e90045df-deb5-41ab-a285-c6b1573ae0f6 MEDIUM 6.4 The Kona Gallery Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Kona: Instagram for Gu… wordfence
e8f2330e-d319-4832-b1b0-1ea702a34026 MEDIUM 6.4 The Kanpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1 due… wordfence
e8d7ace3-af34-4951-810b-87923ef2ec30
< 1.4.2
MEDIUM 6.4 The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget link URL va… wordfence
e8d042be-e272-4e2d-93ec-83a0a42ecd51
< 1.20.7.13
MEDIUM 6.4 The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in ve… wordfence
e8cadb97-2f3e-4b00-ad00-118cf23d1592 MEDIUM 6.4 The Event Registration Calendar By vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
e8b1f60a-3a13-4679-af3e-d6f95fd83cea
< 2.0.0
MEDIUM 6.4 The Gutenverse News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘elementId’ parameter … wordfence
e8a78f06-1af2-462e-b328-0e9e603ad904
< 3.4.10
MEDIUM 6.4 The Real Cookie Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in … wordfence
e8a69fa8-c2a8-4d63-8db4-823122632b3a
< 1.0.15
MEDIUM 6.4 The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow h… wordfence
e897617c-9d26-4de8-93ce-a9b177d28bc5
< 5.6.0
MEDIUM 6.4 The Geolocation IP Detection plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
e8852d39-e34a-45d3-aee8-1ccbfc0ab238
< 8.6.8
MEDIUM 6.4 The Soledad theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pcsml_smartlists_h’ parameter … wordfence
e86c080d-202c-4c41-b9cc-c35249aabba5
< 7.1.2
MEDIUM 6.4 The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
e842ce50-0117-4564-9551-482278dd5c11 MEDIUM 6.4 The CC Circle Progress Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
e834a211-ccc8-4a30-a15d-879ba34184e9
< 2.6.5
MEDIUM 6.4 The Copy Anything to Clipboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'copy' shortcode in… wordfence
e8260829-49a6-4ec0-8771-25d1cce8cc8c
< 5.5.37
MEDIUM 6.4 The WP Data Access plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5… wordfence
e814f798-5ebc-4bea-838f-d0a803f9bdbc MEDIUM 6.4 The Simple Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inc… wordfence
e8119092-d513-4e6c-ab83-d4a49ec66281 MEDIUM 6.4 The Shortcode Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortco… wordfence
e7fe482e-a4e8-411c-97a4-a32ccf5b3682
< 3.2.35
MEDIUM 6.4 The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
e7f90a88-6c19-4adf-8282-2d77234fcc11
< 3.2.8
MEDIUM 6.4 The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via numerous rendering param… wordfence
e7f86396-2f3f-4cd6-b3d4-e518b074a579 MEDIUM 6.4 The PixFields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.7.0 … wordfence
e7ddc418-9458-4335-afdc-6d40c7e23060
< 1.4.4
MEDIUM 6.4 The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a regex bypass in nsp_shortcode f… wordfence
← Prev 503 504 505 506 507 508 509 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top