πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 513 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e1012821-dae9-4fed-9f18-90eef50114ac
< 5.4.3
MEDIUM 6.4 The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
e10127aa-a5a5-4394-8b54-b57ba1369d77
< 6.12.11
MEDIUM 6.4 The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho… wordfence
e0fdee40-9d60-4657-9e2b-42d548dea1c0
< 1.0.2
MEDIUM 6.4 The MomentoPress for Momento360 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's short… wordfence
e0f7bba4-76c3-4904-bd96-2074147b33f5
< 1.1.2
MEDIUM 6.4 The Z Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u… wordfence
e0f787cd-af81-4ba4-8ee1-5e01f06a00b0
< 6.1.14
MEDIUM 6.4 The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
e0e44e96-bd19-47a6-ae7b-e387067bcc8d
< 1.7
MEDIUM 6.4 The Barter theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6 due to… wordfence
e0da2b93-84c6-4228-868f-0c5bfa1e0cf4 MEDIUM 6.4 The S-DEV SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.88 d… wordfence
e0d8ce01-ae59-4e27-bdd1-1ed58590f921
< 1.0.39
MEDIUM 6.4 The Checkout for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
e0d26495-4cab-40f0-842b-90e51a410e42 MEDIUM 6.4 The Category Post Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
e0b81941-ae2b-451a-ae72-07fd72f70a95
< 3.2
MEDIUM 6.4 The Posts List Designer by Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's s… wordfence
e0b4267b-2929-489b-86b8-cd256708c5bd MEDIUM 6.4 The Eulerpool Research Systems plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aaq' … wordfence
e0b26af2-d559-49bf-841a-1974360b3ad6
< 2.5.36
MEDIUM 6.4 The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to DOM-Based Stored Cros… wordfence
e0a12c2f-5101-4e7f-b55b-b34421c80596 MEDIUM 6.4 The Lewe Bootstrap Visuals plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
e07a874f-1ae8-4a3c-bbfe-33eb81052513
< 1.12.4
MEDIUM 6.4 The URL Shortify – Simple and Easy URL Shortener plugin for WordPress is vulnerable to Server-Side Request Forgery in … wordfence
e06fb465-4c72-49a8-af35-ff6d629ff9a0
< 3.8.6
MEDIUM 6.4 The WooCommerce Product Table Lite plugin for WordPress is vulnerable to unauthorized post title modification due to a m… wordfence
e0698d00-6098-4c5b-9487-2fb8d4e5176f MEDIUM 6.4 The WP Notes Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
e05f07fa-80df-4e61-951a-b6088bce0db1
< 1.38.0
MEDIUM 6.4 The Web Stories plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.37… wordfence
e055c319-1aeb-4a97-98d1-3b38e61f30f0 MEDIUM 6.4 The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'envato' shortc… wordfence
e04eb409-b47b-4b9d-b29b-24f7bbaaf5b4
< 9.113.4
MEDIUM 6.4 The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
e047123d-fffb-4fe4-9746-98251c8c2419
< 1.7.5
MEDIUM 6.4 The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
e037d22a-3d4d-4f70-a749-6d6c552c7553
< 4.6.21
MEDIUM 6.4 The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headline' parameter in th… wordfence
e02c5817-7a54-4958-a076-71e5e7729cda MEDIUM 6.4 The Posts map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' shortcode attribute in al… wordfence
e01f5bd8-de0f-48aa-8007-61a0ebd0ebf3
< 1.54.0
MEDIUM 6.4 The VK Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tag Edit functionality in versio… wordfence
e01dd955-fa25-4cb2-8ab8-a648816857f1
< 8.61
MEDIUM 6.4 The IdeaPush plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.60 du… wordfence
e0169bd4-d1bd-494f-a11a-80fc93c36b91
< 2.0.26
MEDIUM 6.4 The Captivate Sync plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
← Prev 510 511 512 513 514 515 516 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top