πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 507 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e7cf069b-2bb8-4dd8-97aa-2994991b60ab MEDIUM 6.4 The Bg Patriarchia BU plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
e7bb5c89-93db-4454-a16d-b99fc14737f8
< 1.1.0
MEDIUM 6.4 The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
e7b6af5a-ad44-4dd6-9ce1-6fcbd28f8ebe
< 1.3.0
MEDIUM 6.4 The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's infobox… wordfence
e7a96a64-4df2-462c-a48b-215a2e19edab MEDIUM 6.4 The Custom Team Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
e778399f-f7fe-47c5-9722-b833d78f475c MEDIUM 6.4 The Animated Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'auto-downloader… wordfence
e77082a7-dd65-40e9-a1be-0144afa869ef
< 6.8.1
MEDIUM 6.4 The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipula… wordfence
e7637e96-3afe-46af-b99d-70abe9ca3e20
< 2.0.3
MEDIUM 6.4 The Euro FxRef Currency Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cur… wordfence
e75f7e1a-f3bb-4b24-bf04-b83d0e572551
< 3.10.8
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event … wordfence
e75815a3-2414-47f3-b0c4-e5d3e2cb369d
< 2.7.11
MEDIUM 6.4 The WP Carousel Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted fancybox `data-captio… wordfence
e75313c5-dbc9-4a33-898e-47d8fd299a42
< 1.2.4
MEDIUM 6.4 The AutoListicle: Automatically Update Numbered List Articles plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
e730114e-bbe1-4385-84cc-a5484acc9da7
< 2.5.11
MEDIUM 6.4 The Jobs for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
e7279f74-c2bd-4601-b8d5-0effe43705a5 MEDIUM 6.4 The Easy Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery shortcode post … wordfence
e7263e89-94b2-42e6-a7ed-a86579ce649e
< 1.5.8
MEDIUM 6.4 The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo… wordfence
e722f6e4-39ec-465d-b897-73de95edf7bf
< 2.7.8.1
MEDIUM 6.4 The JetElements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
e71386ea-0546-4aa7-b77a-e1824e80accc
< 4.8.1
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in… wordfence
e7021881-2ce9-4c8b-bcfa-6886cce649d9
< 1.7.2
MEDIUM 6.4 The Threepress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'threepress' shortcode… wordfence
e6f7fa35-a5b4-4dfd-8be8-17b7b8703c6d
< 1.0.24
MEDIUM 6.4 The Spexo Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countd… wordfence
e6f6dab2-da03-43b6-b9c1-ebc6a7e1d1c9 MEDIUM 6.4 The WooCommerce Product Carousel Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… wordfence
e6eea2cb-a2a9-4f65-9aea-b88565e47503
< 5.7.2
MEDIUM 6.4 The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to SQL Injecti… wordfence
e6ebe12c-17ed-4be9-8af7-4c822b753af1 MEDIUM 6.4 The Responsive Progress Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rprogress… wordfence
e6ebce82-6260-489e-b0b1-5037a0100626
< 1.2.2
MEDIUM 6.4 The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜yrc_lang[Videos]’ paramet… wordfence
e6d14dd6-ff1c-475b-8cff-efc7736124b4 MEDIUM 6.4 The Aparat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1 due… wordfence
e6c3c72d-d2ee-45be-9958-91301a04ee8e MEDIUM 6.4 The Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.1 d… wordfence
e6b35dc7-bd1d-4cdd-808f-41cf2ebfbb1e
< 2.2.5
MEDIUM 6.4 The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute… wordfence
e6b1e4d9-03dc-47e8-ab41-ae9c04dc0132 MEDIUM 6.4 The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-… wordfence
← Prev 504 505 506 507 508 509 510 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top