πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 508 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e6a70210-39bb-44a2-b71a-6f014691a21c
< 1.5.3
MEDIUM 6.4 The Meta Field Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tagName' block attribute… wordfence
e6a65630-0852-4ffc-8c23-295be95bd7f0
< 2.0
MEDIUM 6.4 The Service Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, … wordfence
e69ca7ef-4d7c-4846-80cb-20cd04a90e17
< 5.2.8
MEDIUM 6.4 The Meow Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.2… wordfence
e699f521-9133-41b0-b667-528da78fec06
< 3.6.1
MEDIUM 6.4 The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem… wordfence
e694ef1a-3e81-4995-a96b-2417cb308ce6
< 1.3.0
MEDIUM 6.4 The Logo Carousel – Clients logo carousel for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
e69392a8-da0a-47af-b851-0bc36727ff5a
< 2.3.4
MEDIUM 6.4 The Firelight Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
e66b5c12-3acb-41f7-ae5f-8a9130053e45
< 5.3.4
MEDIUM 6.4 The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up t… wordfence
e65ff338-579d-4e42-842b-2a54a13eaba4 MEDIUM 6.4 The Photospace Responsive plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
e649765f-c051-438e-ba9a-df9a91fef428
< 7.3.10
MEDIUM 6.4 The Zotpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all version… wordfence
e6460406-da83-4dad-97a5-fe961f0c46fc MEDIUM 6.4 The Tippy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tippy shortcode in versions up to, a… wordfence
e63c566d-744b-42f5-9ba6-9007cc60313a
< 1.58.8
MEDIUM 6.4 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters i… wordfence
e637044d-9b49-4de5-b8b8-d48a0e5e1afc
< 3.19.20.1
MEDIUM 6.4 The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ulti… wordfence
e6201ab2-f29b-4790-a1a6-4789b108f546
< 1.2.4
MEDIUM 6.4 The WP Delete User Accounts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
e61ced65-b65d-44e5-b9bc-b7081c38089f MEDIUM 6.4 The ARPrice plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.3 du… wordfence
e60d4528-2ec5-4a4b-be77-0fc012c13720
< 3.15.2
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' p… wordfence
e6030712-ae4f-4cdb-a500-dff689947ff3
< 10.2.4
MEDIUM 6.4 The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all ve… wordfence
e5fed63c-41bb-4f60-a50f-5ee190c76156 MEDIUM 6.4 The Google Visualization Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
e5d3239b-0f65-46f7-977b-9995542a6eb9
< 2.7.5
MEDIUM 6.4 The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's … wordfence
e5cc30d9-c73c-440d-a592-08e85270efdb
< 2.3.9
MEDIUM 6.4 The Responsive Gallery Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode… wordfence
e5c188e0-bc5d-4512-b568-dce9ef9b8c06 MEDIUM 6.4 The Ultimate Image Hover Effects plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
e59cad7f-2da0-4c73-8be2-6bedb1bf6645 MEDIUM 6.4 The Saitama Addon Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
e59b75cf-491a-4894-8a4a-567832b47048
< 2.0.0
MEDIUM 6.4 The flowpaper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions u… wordfence
e58475f4-a07a-4393-a74d-9ba2760401ee
< 1.5.2
MEDIUM 6.4 The Hello Bar Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
e55742de-9eaf-48e4-8d5d-ea980dfa17cf
< 3.13.2
MEDIUM 6.4 The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
e553135d-88e0-4840-99ad-9514c2243b7d
< 2.8.3
MEDIUM 6.4 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scriptin… wordfence
← Prev 505 506 507 508 509 510 511 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top