πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 510 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e413fbfd-fc09-4b84-a8b9-231434e0681b MEDIUM 6.4 The Social Media Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
e40cba5c-455c-44ba-bba2-c825697b837a
< 3.9.19
MEDIUM 6.4 The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
e3f77721-e093-41ae-a59b-3af007ac1389
< 5.5.0
MEDIUM 6.4 The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
e3f71928-3f1d-4c15-8655-41cdfb707370
< 2.0.40
MEDIUM 6.4 The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the className parameter in the About Me… wordfence
e3f3ff3b-d621-46d4-a98a-e5ebf65ddace MEDIUM 6.4 The TweetScroll Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… wordfence
e3f0a20b-d572-4040-b5b6-ede0aec4e2b0
< 5.6.1
MEDIUM 6.4 The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordP… wordfence
e3eec839-9009-48de-80c8-911dc9b545ba
< 7.5.45.7212
MEDIUM 6.4 The FV Flowplayer Video Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, … wordfence
e3ee4563-cf28-42f6-8b50-fd996ad90152
< 11.5.7
MEDIUM 6.4 The Greenshift plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 11.5.… wordfence
e3ed233d-7a14-4005-8a6d-df9a154268d5 MEDIUM 6.4 The WP Category Dropdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
e3e88dc0-4798-4da8-87cf-4c398acc622c MEDIUM 6.4 The Easy Jump Links Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `h_tags` parameter i… wordfence
e3e3c9dc-985a-48fb-8300-add83046100a
< 1.3.5
MEDIUM 6.4 The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
e3e3ac84-dd82-42b0-80b9-c876731170d5
< 2.0.6.1
MEDIUM 6.4 The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is … wordfence
e3d21ebb-52de-4b25-b9e9-5d6f3284cf94 MEDIUM 6.4 The Lava Directory Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(… wordfence
e3bcc0aa-281f-4c59-b3de-dde4277cc989
< 6.2
MEDIUM 6.4 The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a… wordfence
e3bb88e9-e410-4ff7-b342-72c7b375dff1
< 3.1
MEDIUM 6.4 The OpenPOS Lite – Point of Sale for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
e38e8450-743f-47e7-931e-4c2636bd42b4
< 3.15.0.5
MEDIUM 6.4 The FunnelKit Funnel Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
e3593dfd-7b2a-4d01-8af0-725b444dc81b
< 6.2.5
MEDIUM 6.4 The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text fie… wordfence
e3581172-10d8-4b11-95f7-ee1835e29606 MEDIUM 6.4 The LS Google Map Router plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'map_type' parameter … wordfence
e354642a-b817-4490-8738-3edfc3777143 MEDIUM 6.4 The Mind Doodle Visual Sitemaps & Tasks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
e34b6ae5-1370-4058-95dd-5686978ca45b
< 1.7.7
MEDIUM 6.4 The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜ pagelayer_header_code’, 'p… wordfence
e33a2f27-20c2-4963-9558-1eead0515690 MEDIUM 6.4 The Simple Owl Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'num' attribute of t… wordfence
e3305b39-5f7b-493b-80b5-cb925c2710c1
< 1.0.358
MEDIUM 6.4 The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts sh… wordfence
e312e3eb-0da9-4ecf-aec6-86bfe08417f5 MEDIUM 6.4 The Category Post Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'category-po… wordfence
e312db9f-8f02-4c7e-9d49-553a154c95a4
< 1.4.7
MEDIUM 6.4 The Activello theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.6 d… wordfence
e30c6a24-1ec8-4816-b467-c1122b9a8ce1
< 6.0.1
MEDIUM 6.4 The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
← Prev 507 508 509 510 511 512 513 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top