πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 521 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d908e8ac-6864-4951-bbef-8d98ac641912
< 1.0.10
MEDIUM 6.4 The WPBulky plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.9 du… wordfence
d8f94588-635c-44b2-bd7e-af3068734713
< 1.3.40
MEDIUM 6.4 The Materialis Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown shortcode in v… wordfence
d8f40034-c868-4337-bf0a-385a961f9c35
< 2.0.0
MEDIUM 6.4 The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.4… wordfence
d8e64525-6080-40f3-a296-389b800a5e8a
< 2.8.5
MEDIUM 6.4 The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor… wordfence
d8db8ed5-ebeb-4102-928f-fe417e429ad2
< 7.1.6
MEDIUM 6.4 The WP Shortcodes Plugin β€” Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
d8d013ae-a512-454a-bcfc-8725a6928fee
< 2.6.5
MEDIUM 6.4 The Gallagher Website Design plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's login_li… wordfence
d8cf8cff-9d69-4593-afd5-1fc9a10ebd14
< 1.2.3.1
MEDIUM 6.4 The Verbosa theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.3 due… wordfence
d8b449c6-ae13-404a-a356-37d1a08c2a14 MEDIUM 6.4 The Themes4WP YouTube External Subtitles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
d89ff7ef-e184-4993-9496-867f7bf28a4b
< 1.5.3
MEDIUM 6.4 The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
d8987bc5-2bc0-4a92-bcf0-cc3245e15bed MEDIUM 6.4 The Wavr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wave` shortcode in all vers… wordfence
d8805e63-3750-49f8-81dd-bd3353f30c87
< 4.9.4
MEDIUM 6.4 The eID Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜id’ parameter in all version… wordfence
d87f98d1-c281-4f75-a96a-e099c43ed4e1 MEDIUM 6.4 The Accordions – Responsive Accordion & FAQ Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
d8781ed1-6609-4965-9ba2-30e70eac1c1a
< 0.9.5
MEDIUM 6.4 The Lightbox Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the gallery shortcode in vers… wordfence
d87134e8-9d73-4a39-b071-37a5dac033b4
< 4.2.6
MEDIUM 6.4 The Translate WordPress and go Multilingual – Weglot plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
d870ff8d-ea4b-4777-9892-0d9982182b9f
< 1.2.53
MEDIUM 6.4 The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's CP_CALCULA… wordfence
d8693b7d-693f-450a-89ef-e936a8813ca9
< 5.1.4
MEDIUM 6.4 The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Loading Label' setting in al… wordfence
d851ad1f-be74-49eb-9c0d-c1b309581209 MEDIUM 6.4 The WP Simple Anchors Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpanchor … wordfence
d84f9b06-9127-4526-8f17-21608ec2f601 MEDIUM 6.4 The Global Elementor Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button link URL i… wordfence
d84a934f-a807-4968-9db0-9a292767046b
< 2.2.24
MEDIUM 6.4 The Html5 Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
d84797c7-f1fc-4222-aa75-5b44ef96a4a6
< 1.3.1
MEDIUM 6.4 The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
d844ca83-84e5-4b6c-ae26-f300c7328d78
< 4.7.0
MEDIUM 6.4 The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
d8405ba4-5880-4a9e-8196-722e7f59f9a1
< 24.1.12
MEDIUM 6.4 The Snow Monkey Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜data-slick' attribut… wordfence
d83ae3a4-382f-4e64-bf1e-73f953f2f654
< 1.4.21
MEDIUM 6.4 The Xpro Addons β€” 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
d82dd179-a63e-4a83-9b94-c4f3c7ded390 MEDIUM 6.4 The UltraAddons Elementor Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
d82d43b9-4c70-4525-88ba-eec7c81a62c1
< 1.2.8
MEDIUM 6.4 The CWW Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Module2 widget in all versio… wordfence
← Prev 518 519 520 521 522 523 524 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top