πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 512 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e1d7cf90-1a9f-4d88-9dfb-f48481095a0c
< 2.1.9
MEDIUM 6.4 The WP Smart TV plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tv-video-player' sho… wordfence
e1c97b99-ca39-45de-8df9-312ba1573e8d
< 3.0.3
MEDIUM 6.4 The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) … wordfence
e1c4b5e9-e141-4d0d-866a-ff4fb8b68dea
< 1.05
MEDIUM 6.4 The WP-ShowHide for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to… wordfence
e1c11388-fff4-4206-b7b5-3d7e3e0da16a
< 3.0.1
MEDIUM 6.4 The Client Logo Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s)… wordfence
e1bcebb3-920b-40cc-aa5c-24a1f729b28d
< 4.5.13
MEDIUM 6.4 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Store… wordfence
e1b45007-6679-42a4-9d40-1f4630a059f0
< 1.3.0
MEDIUM 6.4 The Vertex Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
e1b19017-b2f0-4c3b-b263-1fbec6f1dce4
< 2.35.2.2
MEDIUM 6.4 The ThemeREX Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio… wordfence
e1b02e83-142f-48f8-88dd-994862d15376
< 6.5.3
MEDIUM 6.4 The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
e1af37ed-fcc6-479c-8c53-25ccb9a8659f
< 3.0.6
MEDIUM 6.4 The Responsive Addons – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for … wordfence
e181f47b-c6d3-4166-9ae2-f49c2ea731a5
< 2.1.6
MEDIUM 6.4 The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
e17c4ed6-b09a-40ca-bcda-2b881056469c
< 2.0.32
MEDIUM 6.4 The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… wordfence
e16da850-6429-4402-ab09-6d2d145bcfd7 MEDIUM 6.4 The Perfect Pullquotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… wordfence
e156bccf-0a70-4794-9b0f-987424dbf657
< 1.7.0
MEDIUM 6.4 The Better Section Navigation Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
e154a12d-8ade-456e-ad64-e1cd419e2b2c
< 1.7.1
MEDIUM 6.4 The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget's… wordfence
e153ca31-56fe-4071-9e0e-786eca875e80
< 1.2.3
MEDIUM 6.4 The Event theme for WordPress is vulnerable to Stored Cross-Site Scripting via author display name in all versions up to… wordfence
e153bb3d-e175-48bd-894c-7ccb8f09fec4
< 1.1.0
MEDIUM 6.4 The Press3D plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 3D Model Gutenberg block in all ve… wordfence
e150d15a-cbc9-4602-831c-2ae8ad2d1b1f MEDIUM 6.4 The Nmedia MailChimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
e14c12ef-0774-4459-9a2c-9a4b633a0efe
< 2.31.5
MEDIUM 6.4 The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Embedded Video(… wordfence
e120698f-c076-4d8f-934c-b4c46f2381ec
< 2.1.6
MEDIUM 6.4 The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typing L… wordfence
e11ecf13-0b3b-4148-abca-677652a68c24
< 2.3.0
MEDIUM 6.4 The WP Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdocs_options[icon_size]' parame… wordfence
e119d542-7cac-47e4-ae13-5382911f1f5e MEDIUM 6.4 The Bulma Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' shortcode attribut… wordfence
e10f391a-6663-4222-8266-ab911c588b76 MEDIUM 6.4 The Smart PopUp Blaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spb-button'… wordfence
e10b668b-b7fc-4626-8e97-15b1fdee93b5
< 0.21.4
MEDIUM 6.4 The Tainacan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.21.3 … wordfence
e10a95e3-e834-4f84-85c1-4a1ffad41b5b
< 2.6.4
MEDIUM 6.4 The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image uploader feature powered… wordfence
e10930fd-fae0-4554-acf3-da81a124f79d MEDIUM 6.4 The ABC Notation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'abcjs' shortcode in… wordfence
← Prev 509 510 511 512 513 514 515 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top