🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 517 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
dcffc816-ff56-4875-b234-91dd1d073721 MEDIUM 6.4 The Contact Us Page – Contact People plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘styl… wordfence
dce8ac32-cab8-4e05-bf6f-cc348d0c9472
< 2.4.6
MEDIUM 6.4 The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
dce0f5dc-a494-4ac3-943a-409f0d817166 MEDIUM 6.4 The Easy Download Media Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
dcdcb29e-48d0-4e22-8e11-0c76b4355268
< 2026.0
MEDIUM 6.4 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
dcd986cd-d6c0-4d8f-8078-ac0ac83572a3
< 1.7.2
MEDIUM 6.4 The My Content Management plugin for WordPress may have been vulnerable to Cross-Site Scripting in versions less than or… wordfence
dcc68b62-7dd1-47d4-bbc5-d0237b7c85e7
< 2.6.23
MEDIUM 6.4 The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver… wordfence
dcc5a611-23bf-499e-8141-684458d9ce3b
< 1.13.3
MEDIUM 6.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in all versio… wordfence
dcbe0c72-d518-45d3-a220-896a51071b26
< 0.8.9.4
MEDIUM 6.4 The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acfe_for… wordfence
dc8f6991-cdde-4c14-9f1b-35fe83d200f9 MEDIUM 6.4 The 코드엠샵 소셜톡 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
dc7ff863-3a8e-41cd-ae20-78bb4577c16a
< 5.4.2
MEDIUM 6.4 The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and … wordfence
dc7099d7-94fd-42be-a921-bfcad43ae252
< 2.0.47
MEDIUM 6.4 The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘has_field_link_rel’ parameter … wordfence
dc6dcbc1-7343-4a8c-937a-5a39d8acb602 MEDIUM 6.4 The Alley Elementor Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
dc686a35-4ce3-4359-a7d3-e6459e2f5dfe
< 2.1.3
MEDIUM 6.4 The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's T… wordfence
dc59510c-6eaf-4526-8acb-c07e39923ad9 MEDIUM 6.4 The Font Awesome 4 Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fa' and 'fa-stack' s… wordfence
dc54b1c2-88fc-4b9b-901d-57bbc079c616
< 28.2.1
MEDIUM 6.4 The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 28.2 due … wordfence
dc4e59ba-9732-4c0c-a89f-866f274661d9
< 1.6.0
MEDIUM 6.4 The Get Use APIs – JSON Content Importer plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers… wordfence
dc41c4e6-8c8a-4132-b40d-b21557bc3fd5 MEDIUM 6.4 The StylePress for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
dc3c7201-6d4f-4e6d-98e0-292f41519203
< 4.2.0
MEDIUM 6.4 The IP Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.0… wordfence
dc333949-de1e-493a-badd-3be1c9060503 MEDIUM 6.4 The Intl DateTime Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ paramete… wordfence
dc1ebc34-d728-42b4-92b4-9e1a4ebd88b2
< 1.0.8
MEDIUM 6.4 The Buk for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buk' shortcode… wordfence
dc057069-15cd-477f-9106-e616e919c62f
< 4.10.24
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widg… wordfence
dc024183-0244-4ef9-9171-057ecd1c3e1d
< 4.2.0
MEDIUM 6.4 The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all v… wordfence
dbf7e7b0-dff7-406c-91a3-4ceddfeda21f
< 7.6.6
MEDIUM 6.4 The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
dbf491d6-e546-4e3f-88c2-237b647a2b1e MEDIUM 6.4 The Delicate theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter within the theme'… wordfence
dbe53b09-84c6-4fb6-9a79-1e4987678129
< 1.8.25
MEDIUM 6.4 The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_css_id’ parameter w… wordfence
← Prev 514 515 516 517 518 519 520 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top