πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 514 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e00f69d6-df33-4179-843b-98f8ed034e4a MEDIUM 6.4 The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes i… wordfence
e004bba3-d281-4f84-a941-a6c5b64b9dcd
< 1.30
MEDIUM 6.4 The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
dfed10b0-f2eb-4228-b835-2a29c13e4a3f
< 3.2.37
MEDIUM 6.4 The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-… wordfence
dfeaff92-165a-4006-8e52-a99ae6b68dd9
< 3.4
MEDIUM 6.4 The DSGVO snippet for Leaflet Map and its Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
dfdebeab-89f6-49b8-a38f-de2a8df7a7e8 MEDIUM 6.4 The Simple post listing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_name' parameter… wordfence
dfb6961b-1398-409d-ada2-cf5424cb2b73
< 5.9.16
MEDIUM 6.4 The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
dfb0da20-99f1-4bf1-8b30-3c8d15bf9679
< 3.2.85
MEDIUM 6.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
df96f58a-bc6e-47e7-a465-4aebdb264512
< 1.4.7
MEDIUM 6.4 The News Kit Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, a… wordfence
df93727c-2d2f-4e13-8c89-3ffb93975180
< 3.3.00
MEDIUM 6.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_login_form… wordfence
df81b1e4-65f6-4df5-8814-1c007870df9a
< 14.6
MEDIUM 6.4 The Crossword Compiler Puzzles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
df6e347c-e6a2-42c3-ae92-502d32e4f591 MEDIUM 6.4 The Eventbee RSVP Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
df6d2689-c9e2-4913-924c-7793f8546a8e MEDIUM 6.4 The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
df5cd6e7-e821-403f-a048-25c2ca1fb2de
< 3.1.33
MEDIUM 6.4 The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pp_link' s… wordfence
df4b554a-0336-404c-b06c-2bc98c99997d
< 3.20.8
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_elementor_dat… wordfence
df4ada5f-6008-40b9-ad83-c6af82e64e9f MEDIUM 6.4 The Display Pages Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'column_count' par… wordfence
df4aa0e3-a365-435d-bd89-8b8648b6361b
< 1.3
MEDIUM 6.4 The Document Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
df417809-153f-4d05-a495-bfc17897a5bf
< 1.7.1
MEDIUM 6.4 The Additional Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
df40eb21-2080-4de5-9055-09246a8a275e
< 2.10.31
MEDIUM 6.4 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Table widge… wordfence
df35d8c6-55ec-4cf5-8055-93ec5193c0a4
< 2.5.1
MEDIUM 6.4 The Options for Twenty Seventeen plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social-links' sh… wordfence
df324557-9ead-46aa-a019-89d1d5ca6d9c
< 3.3.0
MEDIUM 6.4 The Asgaros Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.… wordfence
df30f21a-cd3a-4391-9f59-81538fefabdc MEDIUM 6.4 The Xavin's List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xls' … wordfence
df2854c4-5d57-4c39-a28f-41dab36a086e MEDIUM 6.4 The HotelRunner Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hotel… wordfence
df21d1f2-2a72-4a9c-8542-3a0c9b732497 MEDIUM 6.4 The Envision Page Builder – A collection of WordPress Gutenberg blocks & templates plugin for WordPress is vulnerable … wordfence
df109949-bd7f-4077-84a8-13750fc70238 MEDIUM 6.4 The Nemesis All-in-One plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
df0dcdf4-fcb1-4832-b39b-4ec3ee980506
< 5.2
MEDIUM 6.4 The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not valid… wordfence
← Prev 511 512 513 514 515 516 517 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top