🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 522 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d8272233-afb3-46f1-ab85-189a3923e29d
< 3.4.9
MEDIUM 6.4 The Virtue theme for WordPress is vulnerable to Stored Cross-Site Scripting via a Post Author's name in all versions up … wordfence
d81c62ae-99b7-48cf-87e5-dcc5c9c851ba
< 2.1.1
MEDIUM 6.4 The The Pack Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
d7fe128e-02b7-4838-8575-db09d33d2340 MEDIUM 6.4 The SVG Case Study plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all version… wordfence
d7fb1b31-3393-4fd4-9cef-35fda1258b5e
< 3.0.2
MEDIUM 6.4 The Quotes llama plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0… wordfence
d7fa63b7-2e7f-4ed5-96b9-ae06d429af47
< 3.3.101
MEDIUM 6.4 The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ para… wordfence
d7ed9911-5505-411e-b899-0791b1920bee MEDIUM 6.4 The Zoho Billing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1… wordfence
d7e4dd2c-5f6a-4bce-a46b-7bdd9d460804
< 8.6.5
MEDIUM 6.4 The Geo Controller plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8… wordfence
d7e18997-90be-4fa4-aa4f-3b79544e00f5
< 3.2.1
MEDIUM 6.4 The Save as PDF plugin by Pdfcrowd plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… wordfence
d7d698be-fae6-4960-912a-1078ea407031 MEDIUM 6.4 The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribut… wordfence
d7c80143-c328-4cd1-95db-67de2edc058c
< 8.6
MEDIUM 6.4 The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several sh… wordfence
d7b86055-5157-4751-9039-9c563745e383
< 2.0.0
MEDIUM 6.4 The CBX Map for Google Map & OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… wordfence
d7b566f6-58d9-448e-bccf-8806ef1ed3c2
< 2.0.17
MEDIUM 6.4 The Post Grid Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title_tag parame… wordfence
d7b40a67-40b2-4f9b-9f31-0afaeaebbeab
< 1.2.7
MEDIUM 6.4 The WP Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions… wordfence
d7b11375-a709-4926-8065-a9dfc9fa4f9a MEDIUM 6.4 The Dideo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dideo' shortcode in versio… wordfence
d7ac0683-120f-4e76-9d44-5ee1c789b2c8 MEDIUM 6.4 The Text Toggle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute of… wordfence
d7a298c9-c688-4c39-bd68-2a58ff8d1402 MEDIUM 6.4 The Post List Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
d79ffe25-8acd-4b52-ac14-7df62247c0d4
< 1.5.4
MEDIUM 6.4 The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable… wordfence
d798406b-2b7f-4ca0-8d05-8aff4bf44dd8
< 4.9.3
MEDIUM 6.4 The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_ean_p… wordfence
d78ac022-6f07-4da5-a657-cafa78dc1845
< 4.1.1
MEDIUM 6.4 The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod… wordfence
d783b6ca-940c-4939-b96a-339419d8ed56
< 1.4
MEDIUM 6.4 The Digiseller plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ds' shortcode in all … wordfence
d77e94ad-2bb7-442d-be67-b4f42b3b3107
< 3.12.10
MEDIUM 6.4 The Leaflet Maps Marker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
d77db5be-fa72-45f8-ad87-82cb0d0b4c94
< 1.9
MEDIUM 6.4 The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Block i… wordfence
d77c8096-40b1-4ac7-881f-6aed98da6752
< 2.8.51
MEDIUM 6.4 The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_medi… wordfence
d76052f8-34b3-4930-a5bf-182420b07968
< 0.10.7
MEDIUM 6.4 The DICOM Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dcm' shortcode in … wordfence
d74e8541-9726-4bc2-9fbd-f6016490e0ea
< 1.2.0
MEDIUM 6.4 The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
← Prev 519 520 521 522 523 524 525 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top