🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 519 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
dabcc606-04ab-4fb0-bf3c-d3ad915b8904 MEDIUM 6.4 The CM CSS Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' shortcode attribute i… wordfence
dab587c3-54f3-4619-8de0-8740d6451f96
< 3.4.0
MEDIUM 6.4 The 우커머스 네이버페이 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mnp_… wordfence
dab150ce-71b3-49ec-b3bf-ebff74d7b542
< 2.2.1
MEDIUM 6.4 The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
daa38c2c-9992-400b-acef-dcd37f9c7269 MEDIUM 6.4 The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repea… wordfence
daa30b1b-cb8f-43fd-8329-c64b4024408f
< 3.12.12
MEDIUM 6.4 The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
da97a395-64b8-4efd-b189-f917674b1c18
< 6.6.5
MEDIUM 6.4 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
da94a7dc-f666-44fd-9f76-e610cbd2b610
< 3.1.0.5
MEDIUM 6.4 The Easy Digital Downloads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(… wordfence
da9089a2-420f-4744-96d1-46c050a95328
< 1.1.8
MEDIUM 6.4 The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '… wordfence
da86c6e0-2cff-4aca-b440-ef3fc1f61324 MEDIUM 6.4 The amr shortcode any widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortco… wordfence
da80ee88-71ca-4200-a853-7ffcbd21448a
< 3.2.10
MEDIUM 6.4 The Blockspare plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.9… wordfence
da6dcf5c-bb70-4227-a784-55cf28980308
< 3.5.6
MEDIUM 6.4 The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem… wordfence
da6bf521-0c22-4839-8fa6-a0d67e28cfbd
< 1.1.8
MEDIUM 6.4 The Ova Advent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all vers… wordfence
da68f210-ad67-4027-80e6-efd1c3562eed MEDIUM 6.4 The Cool Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
da3b8de2-f620-40a7-a44a-c4fcb6d57d8c
< 3.0.0
MEDIUM 6.4 The RSS Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rfw-youtube-vide… wordfence
da308b0c-a892-4bd7-b242-3bbf9ad709ad MEDIUM 6.4 The Roseta theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.0 due … wordfence
da2d8494-aea3-4a1e-9eca-946c0bd390cd
< 1.9.11
MEDIUM 6.4 The WP Video Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in… wordfence
da1ef273-417a-47f6-adf9-dbd5747a8c3b
< 1.1.3
MEDIUM 6.4 The Video & Photo Gallery for Ultimate Member plugin for WordPress is vulnerable to Server-Side Request Forgery in all v… wordfence
d9fe750f-5d8f-4c47-9d75-d928f1367fa8
< 2.0.3
MEDIUM 6.4 The Cricket Live Score plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cricket_score… wordfence
d9fe53e3-1916-4de2-91a6-83e823fc6e91
< 2.0.6
MEDIUM 6.4 The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ver… wordfence
d9f257a9-d447-407c-83ae-3cc99254be3f
< 7.9.9.2
MEDIUM 6.4 The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress i… wordfence
d9f1ea27-463f-477e-b3c0-691ed84e34a4
< 3.16.3
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
d9ed939c-dc9c-46e8-9b23-0a3e5733e8d5
< 2.12.9
MEDIUM 6.4 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu… wordfence
d9d37248-d024-4465-a1e6-d8f2d3a2e02f
< 8.3.6
MEDIUM 6.4 The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ a… wordfence
d9d000ad-a8f1-44c8-8c11-4a1982e1e6e4
< 2.0.1
MEDIUM 6.4 The Loan Comparison plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'loancomparison' … wordfence
d9c4e963-afdd-4a54-80ac-8dd18075a934
< 5.10.4
MEDIUM 6.4 The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.10.… wordfence
← Prev 516 517 518 519 520 521 522 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top