πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 515 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
df08ecbe-0a14-4522-9e2d-5398f57c6acd
< 1.3.12
MEDIUM 6.4 The Podlove Subscribe button plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
defc5b5a-243d-4564-a9f8-3ecf3538129b
< 3.1.1
MEDIUM 6.4 The Notice Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several style settings in versions … wordfence
def8be8e-142e-4f8c-85e0-67e46a349abe
< 2.7.2
MEDIUM 6.4 The Auto Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
deef6900-531f-42f1-89a4-28ec62817d0b
< 1.2.2
MEDIUM 6.4 The Accordion title for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
dee7d15e-61f5-4774-8ae9-060634b9662c
< 1.06
MEDIUM 6.4 The WP-ShowHide plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.05… wordfence
dedd24e6-ac0c-48cd-a76a-8fb61d2c3c0f
< 7.9.9.2
MEDIUM 6.4 The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress i… wordfence
dedb1a15-933b-4e8a-b82d-a154414c61ba
< 2.1.8
MEDIUM 6.4 The Print-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versi… wordfence
ded2f366-375c-4cf6-9cbd-c969a3b3d6d5
< 2.7.3
MEDIUM 6.4 The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up… wordfence
debaf111-012a-477f-ae09-bdaf330e6b0f
< 3.2.6
MEDIUM 6.4 The Nav Menu Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
deba0a29-7fe5-4f94-bee6-9d01e023215e
< 7.4.3
MEDIUM 6.4 The WP Shortcodes Plugin β€” Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a… wordfence
deac4e1d-edeb-4d66-a152-6dca84e60b68
< 7.3.11
MEDIUM 6.4 The Zotpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.3.10 … wordfence
de9dcdc1-cdd3-4c10-84b2-938d5263e98e
< 3.33.0
MEDIUM 6.4 The WishList Member X plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
de931a65-c898-4b1d-99ce-20dd646bcbb0 MEDIUM 6.4 The Administrative Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'login' and 'log… wordfence
de8b14c0-00f8-4c4d-ae78-bc29a1e5007c
< 5.30.3
MEDIUM 6.4 The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up t… wordfence
de895d41-a59d-4449-ba5d-f9efd79f534c MEDIUM 6.4 The Extra Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
de805955-b7c7-455b-bc1a-69b8a14ba79d
< 2.4.5
MEDIUM 6.4 The WC Vendors Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes… wordfence
de63f5bf-9cf5-428d-80da-c0030988b4a6
< 6.6.0
MEDIUM 6.4 The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in vers… wordfence
de602cf8-cc02-4459-aa23-5d8236048bca MEDIUM 6.4 The IDer Login for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ider_lo… wordfence
de4dfcc7-fcc0-46e5-8452-98783007368d
< 6.1.6
MEDIUM 6.4 The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
de379f74-660a-4e59-b1c4-4b88dff8a843
< 27.0.3
MEDIUM 6.4 The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
de3498d3-74d5-4450-b91f-cd41e00c3d6c
< 3.0.5
MEDIUM 6.4 The Logo Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.… wordfence
de30e953-4995-4b98-a3b8-c3613a91d006
< 2.4.8
MEDIUM 6.4 The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.… wordfence
de2f93f9-1789-4fdf-ac83-b2cfe44fdafa MEDIUM 6.4 The byBrick Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
de25459d-9e19-4e3e-982f-0b34fa89dc30
< 11.15.16
MEDIUM 6.4 The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podca… wordfence
de207181-0163-4222-ac16-d7b74179ff9b
< 4.10.53
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Medi… wordfence
← Prev 512 513 514 515 516 517 518 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top