🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 511 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e2fef3b8-4a69-4c4e-b316-ab6c7e33e68f
< 0.5.8.4
MEDIUM 6.4 The Off-Canvas Sidebars & Menus (Slidebars) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
e2edeb63-56ad-45e7-9e85-cdf0a8ef41e7
< 2.4.15
MEDIUM 6.4 The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
e2e755c7-7d1e-45f7-9d0b-2df1ef0bdd02
< 2.6.4
MEDIUM 6.4 The Animation Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'weather_st… wordfence
e2d35599-2402-4837-97a3-707cd33d439a
< 1.3.7
MEDIUM 6.4 The Countdown Timer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
e2d2566e-841a-49e6-86b5-33e2a7da4361
< 1.0.332
MEDIUM 6.4 The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
e2b10c7e-07ce-4edf-8757-b0da6dcfd43e
< 2.2.9.1
MEDIUM 6.4 The JetTabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.9 du… wordfence
e2a6d017-93e4-40c6-a7d1-07e00faecf36
< 2.0.28
MEDIUM 6.4 The Beds24 Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's beds24-link… wordfence
e29ea7dd-14b8-45d3-a87e-3f58de88af4c
< 5.4.0
MEDIUM 6.4 The WP Plugin Info Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerid’ para… wordfence
e290f1aa-d20a-4e76-b77b-3e5b79e9d379
< 1.4.3
MEDIUM 6.4 wordfence
e290e142-bd18-4441-b3d0-1a84e1faeaf7
< 2.5.2
MEDIUM 6.4 The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SwipeBox in all … wordfence
e28b78c3-c370-4076-836e-9f61acba064c
< 8.3.6
MEDIUM 6.4 The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘text_align… wordfence
e288b26f-de4e-4486-b86d-f4d8c881ae75
< 3.1.52
MEDIUM 6.4 The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
e285849f-886e-49ba-bb43-8c67655fe239
< 3.1
MEDIUM 6.4 The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
e27afce1-4108-47fd-9f96-ea7743df771b MEDIUM 6.4 The Penci Podcast plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
e276cc49-2da1-4e2f-bb64-28ffe6ec9acf
< 20240106
MEDIUM 6.4 The Private Google Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
e26ccd06-22e0-4d91-a53a-df6ead8a8e3b
< 2.7.0
MEDIUM 6.4 The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' p… wordfence
e264af7c-84bb-4bfa-a433-39dd94a9d83b
< 3.1.4
MEDIUM 6.4 In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accept… wordfence
e254f0ba-9008-44e9-bf8f-31c9614d6f64
< 1.8
MEDIUM 6.4 The Eveeno plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eveeno' shortcode in all … wordfence
e25157d3-42ac-4dd6-a736-5623a16e5629
< 1.5.9
MEDIUM 6.4 The Formality plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all ver… wordfence
e23f63a0-3061-42e0-a6be-05fa20a174ea
< 9.8.1
MEDIUM 6.4 The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Roundup Recipe Name field … wordfence
e22567fa-456b-4537-a641-7f185ab6d2ba
< 1.4.1
MEDIUM 6.4 The Transcoder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.0… wordfence
e20a34e5-6c1c-4f12-b1d8-aa4b40a5dd00
< 5.1.13
MEDIUM 6.4 The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'table_currency' … wordfence
e1fc6a2e-9c91-4517-8f04-fb3ea65413b8 MEDIUM 6.4 The Zengo Custom Thumbnail Image Gallery plugin for WordPress is vulnerable to Cross-Site Scripting via the shortcode fu… wordfence
e1eb1c7c-9242-43af-b0bf-375cdb182af0 MEDIUM 6.4 The Estatik plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.13 d… wordfence
e1dbd0e2-8c6c-4127-b37c-269af3b7f71c
< 5.5.1
MEDIUM 6.4 The Jetpack CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the client phone number field in v… wordfence
← Prev 508 509 510 511 512 513 514 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top