πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 509 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e54f2e28-7320-4d2d-a416-e46202c08375 MEDIUM 6.4 The Quizlord plugin through 2.0 for WordPress is prone to Stored XSS via the title parameter in a ql_insert action to wp… wordfence
e54e2831-e5e9-43f4-acb6-9cf00fdb4e57
< 6.7.1.8
MEDIUM 6.4 The Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `vc_quizmaker` shortco… wordfence
e54caaf5-f37b-4842-ab3d-8e37cbed58da
< 26.0.9
MEDIUM 6.4 The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or S… wordfence
e5492ad2-52a4-42a3-9170-e8102fcfa38b
< 1.0.0.43
MEDIUM 6.4 The Gallery Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
e53cd64c-9278-48cc-8181-1d6c40a05eb7
< 9.3
MEDIUM 6.4 The wp-forecast plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.2 … wordfence
e52c5628-5535-4214-a788-bc2ce9ae6ba0 MEDIUM 6.4 The Job Board Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
e5252b2f-c1a1-4fec-abaf-ad234affdcfb
< 3.7.24
MEDIUM 6.4 wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js fi… wordfence
e50ef794-f551-4743-91b6-79509e9acf01
< 1.20.3
MEDIUM 6.4 The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.20… wordfence
e4eef7f0-5f09-4618-a3f8-a9e8dabef334
< 3.1.3
MEDIUM 6.4 The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the postTitleTag in all version… wordfence
e4d591a6-4bbe-435b-aef6-ed176c42dca2 MEDIUM 6.4 The WordPress Content Flipper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bgcolor' shortc… wordfence
e4d55309-d178-4b3d-9de6-2cf2769b76fe
< 2.4.8
MEDIUM 6.4 The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in … wordfence
e4d373f3-59ff-4543-86f2-f95efe8c7cdb MEDIUM 6.4 The Shortcode Collection plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
e4b4e4ba-ab66-496a-b77f-8dd77cd16ea8
< 1.0.19
MEDIUM 6.4 The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File upl… wordfence
e4af4769-f897-4d44-93d4-9dbb6f142678 MEDIUM 6.4 The FSM Custom Featured Image Caption plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
e4ac5f28-8727-4205-abe5-7f29a0c4dc5d
< 3.0.1
MEDIUM 6.4 The Ed's Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `social_share` … wordfence
e49da9e7-26a1-442b-b5d0-1da3bcf0e8c9
< 2.2.81
MEDIUM 6.4 The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordP… wordfence
e499408c-c4c5-465c-b883-50d449d684e0 MEDIUM 6.4 The WPThumb plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.10… wordfence
e493d822-6f0c-4349-9af0-6095199a3b51
< 12.0.1
MEDIUM 6.4 The JNews Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 12.0.1 due to insu… wordfence
e485949f-f48e-4a8c-b799-d1a41f36848c
< 1.8.68
MEDIUM 6.4 The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_posts … wordfence
e4696f7a-8b87-4376-b4c9-596eca30b38c
< 3.0.5
MEDIUM 6.4 The Etsy Shop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etsy-shop' shortcode in versions up… wordfence
e45e0ff1-3e74-4eee-a4ff-8ec033599bc3 MEDIUM 6.4 The TweetThis Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tweetthis' s… wordfence
e451df35-8448-4791-859e-969dc97a1aa8
< 1.8.17.0
MEDIUM 6.4 The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, … wordfence
e44ad307-2663-4613-ae53-9ef6208f08f9
< 1.6.0
MEDIUM 6.4 The Structured Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
e44004a9-c705-4e97-83e2-f7db4311a978 MEDIUM 6.4 The WpF Ultimate Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
e41965eb-f8eb-4f40-b8f6-e415dff048cd
< 1.3.0
MEDIUM 6.4 The Image Hotspot by DevVN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hotspot_content' c… wordfence
← Prev 506 507 508 509 510 511 512 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top