πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 516 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
de09d051-d124-4397-bd1c-b193acd6c186
< 1.7.30
MEDIUM 6.4 The WP YouTube Lyte plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lyte' shortcode … wordfence
ddf2ca43-a1d5-4809-b8ad-916b23f71a7d MEDIUM 6.4 The 1180px Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attrib… wordfence
dde2edc7-74dd-4763-b83b-97cfeb2b764c
< 5.7.6
MEDIUM 6.4 The Element Pack Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
dde0cf3a-778b-4b5f-ac0e-600505d918ae
< 6.7.0
MEDIUM 6.4 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Store… wordfence
ddde9db5-3ed7-42f7-97c1-4ff9b9d1f627 MEDIUM 6.4 The DrawIt (draw.io) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
ddcf7901-e9cf-4ca0-87ae-70ecac09d102
< 2.5.2
MEDIUM 6.4 The SVG Support plugin for WordPress defaults to insecure settings in version 2.5 and 2.5.1. SVG files containing malici… wordfence
ddc5c4d7-09dc-45bf-a3c7-5a0757e3110a
< 3.1.15
MEDIUM 6.4 The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the lazy-loading image processing … wordfence
ddbb4bcf-daf7-4ae3-8f42-fce5f1d2c279
< 2.1.3
MEDIUM 6.4 The Table Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜_id’ param… wordfence
ddbac1d2-0589-4c0b-ac22-cba80b211109
< 2.0.16
MEDIUM 6.4 The JetPopup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.15.… wordfence
ddb74878-f200-47cd-a719-d7c2da8167c1
< 1.5.3
MEDIUM 6.4 The Waymark plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.2 du… wordfence
ddb5020f-0480-4123-b064-4f33ae142a5c
< 1.2.1
MEDIUM 6.4 The WC Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.0… wordfence
dd9650e6-7c3c-4510-9749-a3503924855f
< 3.1.32
MEDIUM 6.4 The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcod… wordfence
dd8f5cfa-3431-4617-b2cd-d5a8ce4530f4
< 3.11.0
MEDIUM 6.4 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
dd8c077c-214d-4885-a427-559511f54485 MEDIUM 6.4 The BuddyPress Notification Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
dd87f789-dd71-4274-a836-e9af230161e5 MEDIUM 6.4 The Ad Blocking Detector plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
dd7f112b-9c16-4bc0-a3fa-caeca3d40752
< 1.1.1
MEDIUM 6.4 The GS Coaches plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.0… wordfence
dd62a072-8619-4f51-a52f-2ada7e455cb1
< 2.8.6
MEDIUM 6.4 The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
dd36f50b-f9c9-4ca2-81ed-a4e20fc38e82
< 2.1.10
MEDIUM 6.4 The SuperSaaS – online appointment scheduling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ver… wordfence
dd321fd7-1f3a-4d1c-b832-69423a35fad5
< 5.5.4
MEDIUM 6.4 The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable … wordfence
dd2ec0b3-2784-4506-99f4-05187527fe6d
< 2.7.7
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's An… wordfence
dd201949-d3a1-4fdb-bf98-252fbfd59380
< 5.0.11
MEDIUM 6.4 The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Stor… wordfence
dd1d8aaa-eea0-4723-b9fa-b32d4d7c022e MEDIUM 6.4 The Easy Image Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
dd13eb67-3bd5-41c4-a47f-5f55656ea5b9
< 2.1.15
MEDIUM 6.4 The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blocksy_newsle… wordfence
dd0597d2-07ba-4fb4-bf73-95770f8c3d6b
< 9.0.39
MEDIUM 6.4 The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS… wordfence
dd040ff7-7f30-4097-9492-743a9821589e
< 1.0.2
MEDIUM 6.4 The ThemeMakers Stripe Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'stripe' short… wordfence
← Prev 513 514 515 516 517 518 519 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top