πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 518 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
dbd33d03-81ba-468e-9e25-fe9f13914dbd MEDIUM 6.4 The Simple Tableau Viz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tableau' shortcode in … wordfence
dbcdeda4-85b7-48d6-b89d-1d1756d183d2
< 3.5.1
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before … wordfence
dbca4df8-d5d6-40b5-b897-e249a5a3bb00 MEDIUM 6.4 The Enhanced Paypal Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
dbbea6bf-b795-4837-9dc9-7cb8769ab89f
< 1.3.20
MEDIUM 6.4 The Newpost Catch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's npc shortcode in al… wordfence
dbbdf433-8589-4f5f-b73d-2dba58f684a7
< 2.5.7
MEDIUM 6.4 The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
dbaedb36-6710-48ab-8bb5-e6065fa8df51
< 1.7.0.14
MEDIUM 6.4 The Charitable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versio… wordfence
db8437ee-d917-406d-810d-6b7cbe7976c1
< 1.3.8
MEDIUM 6.4 The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
db836f4b-d31f-4442-89a5-1a400525c598
< 2.6.9
MEDIUM 6.4 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sto… wordfence
db761098-e76a-4be8-8b3d-ec964ecbc01c
< 1.2.2
MEDIUM 6.4 The BP Group Documents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display name' and 'Des… wordfence
db4c9d47-fb54-4f8c-bb82-c72be743458f
< 1.1.1
MEDIUM 6.4 The Alert Box Block – Display notice/alerts in the front end plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
db3a9106-2d90-44fe-a86b-9ea882f56eb4
< 0.3
MEDIUM 6.4 The Contextual Adminbar Color plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜message’ pa… wordfence
db14b141-521b-464d-a638-2228b1a86c2b
< 1.5.113
MEDIUM 6.4 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros… wordfence
db12f986-580e-4e81-8bd2-124393e5d21b
< 1.3.7
MEDIUM 6.4 The Typing Effect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and… wordfence
db0f9aeb-57e4-4966-a80c-e146cd163a6c MEDIUM 6.4 The BWL Pro Voting Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
db0456e7-7d44-442b-9e0b-3390612b55b3 MEDIUM 6.4 The Utech Spinning Earth plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
db0222e2-5a50-43f4-8620-12b97c712dec
< 3.9.2
MEDIUM 6.4 The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
db01bc0a-4508-4fb5-941d-3f1a52528e2b
< 1.3.2
MEDIUM 6.4 The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
dafbabe0-7f25-41e0-9d7a-919a11cc2c70
< 1.0.1
MEDIUM 6.4 The Tutor LMS BunnyNet Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
dafba494-070b-4f49-ab57-768cd989cf61
< 1.3.7
MEDIUM 6.4 The Forex Calculators plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu… wordfence
daf8c172-100a-4f48-9b2d-c415c2a54bc0
< 1.5.3
MEDIUM 6.4 The HTML Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.2… wordfence
daeda8d7-1bff-4258-9953-b4303f1778d0
< 2.4.1
MEDIUM 6.4 The Bilingual Linker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bl_otherlang_link_1 param… wordfence
daeb24e0-7f3f-472f-aee5-be42e374aa52
< 4.3.3
MEDIUM 6.4 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
dae80fc2-3076-4a32-876d-5df1c62de9bd
< 5.1.3
MEDIUM 6.4 Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups li… wordfence
dacfba3e-c1d7-475c-885b-f77b77a65f91
< 1.0.8
MEDIUM 6.4 The Keyword Rank Tracker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in ve… wordfence
dabe0313-e349-4c87-894b-2612db28dcec MEDIUM 6.4 The PQ Addons – Creative Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widge… wordfence
← Prev 515 516 517 518 519 520 521 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top