πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 524 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d683c895-0532-4ffe-a4db-13d9c17426c7
< 11.2.2
MEDIUM 6.4 The Quiz And Survey Master plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
d67e312f-58ad-46d9-a14c-4082ec64442e MEDIUM 6.4 The Image Switcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0… wordfence
d67de4f2-b680-49f8-be95-c2464b70f7d0
< 6.9.1
MEDIUM 6.4 The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Wi… wordfence
d67d5662-0cc7-4b14-a50b-15158f6e4239 MEDIUM 6.4 The Netroics Blog Posts Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜title’ param… wordfence
d673d229-5024-4325-bddc-e52d87a1da62
< 5.0
MEDIUM 6.4 The IGIT Related Posts With Thumb Image After Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
d664d1f9-39b1-424f-a95e-7a480d809c79
< 1.52
MEDIUM 6.4 The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
d661c24e-48f3-4b97-aa34-e46bd3907546 MEDIUM 6.4 The Simple Donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's simpledonate shortc… wordfence
d658e087-8cc7-4653-af3c-407b6f73fb7b
< 2.4.0
MEDIUM 6.4 The Header and Footer Scripts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _inpost_head_scr… wordfence
d652f383-ca3d-440e-a30f-64a50efd65e1
< 6.5.10
MEDIUM 6.4 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Store… wordfence
d650261a-ec0a-4538-ad59-0589712702fa
< 5.4.5.1
MEDIUM 6.4 The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form settings in al… wordfence
d64e6440-0b96-4e81-a0fd-e0839bd78280
< 1.1.35
MEDIUM 6.4 The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
d643e360-e2ae-4bcb-b02b-c4957853425a
< 1.8.5.3
MEDIUM 6.4 The Content Mask plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,… wordfence
d63cd13e-4a16-483f-8165-6c8090ceebab
< 1.1.4
MEDIUM 6.4 The Alert Box Block – Display notice/alerts in the front end. plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
d6332d57-5832-4093-a609-f9c454452815
< 2.6.0
MEDIUM 6.4 The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vuln… wordfence
d62da9a3-3a57-4bbd-b07d-8df39fa14c52 MEDIUM 6.4 The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor do… wordfence
d62d3ca5-5795-46ef-ad8c-4474ff1e504e
< 2.7.4.5
MEDIUM 6.4 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
d62c6a7e-2390-4e27-8419-53aa80b1dbac
< 1.3.2
MEDIUM 6.4 The ChaosTheory theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3 d… wordfence
d621869c-31f7-4243-9815-f6d1bbe469e2
< 1.8.4
MEDIUM 6.4 The Crypto Converter Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
d61d2dc5-7461-460c-8dbc-e32a512d5828
< 8.4.0
MEDIUM 6.4 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
d5fbca66-403e-41bc-8f80-3fb56d4b9c66
< 1.8.3
MEDIUM 6.4 The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulner… wordfence
d5f267a5-012d-4b9a-a59d-9eccb04c557a
< 1.1.3
MEDIUM 6.4 The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo… wordfence
d5ecb52e-6bf0-4168-b0d7-6972d23c9122
< 2.9.5
MEDIUM 6.4 The Real Estate 7 WordPress theme for WordPress is vulnerable to both Reflected and Stored Cross-Site Scripting, Insecur… wordfence
d5e60125-35e2-4d6d-8ea7-078df0b9e55f
< 2.1.0
MEDIUM 6.4 The Donation Block For PayPal for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) i… wordfence
d5d7e59e-962c-45d9-b3be-033bccf4c6b1
< 0.1.1
MEDIUM 6.4 The PhoneTrack Meu Site Manager WordPress plugin through 0.1 does not sanitise or escape its "pht_id" setting before out… wordfence
d5d4aeb1-0a4f-49f1-b5a9-b582e271eae1
< 2.4.15
MEDIUM 6.4 The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image attachment fields (such as 'T… wordfence
← Prev 521 522 523 524 525 526 527 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top