🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 525 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d5d2ff90-9817-490e-8162-ca4860b3ffe3
< 1.8.0
MEDIUM 6.4 The Cooked – Recipe Management recipe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_reci… wordfence
d5d0ccbd-a091-4897-a100-eac75ffa0e3b
< 2.5.0
MEDIUM 6.4 The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Slider… wordfence
d5c29af7-f607-429a-9a1e-f8701fbb9e7a MEDIUM 6.4 The Giphypress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.2… wordfence
d5b5eb2a-4a6a-4a58-93ec-c83a573b8a86
< 1.8.4.8
MEDIUM 6.4 The Charitable plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.4… wordfence
d5a4bfee-5e20-4898-aea2-c7e86718ccca
< 5.1
MEDIUM 6.4 The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.0 d… wordfence
d5a3b416-4434-456e-91c7-24f874e8f959 MEDIUM 6.4 The Shortcode For Elementor Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
d5a3a560-08e6-43b7-b953-4e704eafc49b
< 7.5.52.7212
MEDIUM 6.4 The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' … wordfence
d59a4d69-cf51-44c1-90bf-19be04774c27
< 4.0.0
MEDIUM 6.4 The Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation o… wordfence
d58fe116-0896-46b5-a120-d0fde9680ff1
< 7.5.51.7212
MEDIUM 6.4 The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 7.5.5… wordfence
d58db3d7-65a4-4363-aa36-c6a3089be76d MEDIUM 6.4 The wp-enable-svg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions… wordfence
d5810757-1866-4788-809f-2c68e16a5156
< 4.1.1
MEDIUM 6.4 The Divi Torque Lite – Best Divi Addon, Extensions, Modules & Social Modules plugin for WordPress is vulnerable to Sto… wordfence
d57d3d3f-7669-420f-8d6b-e946edc7eda0
< 6.2.8
MEDIUM 6.4 The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
d5653ebe-7145-4b1c-94f8-ca87ed0dc4f5
< 4.5
MEDIUM 6.4 The EMC – Easily Embed Calendly Scheduling Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
d55bab2a-5e2e-440e-b4fa-03853679ba22
< 3.10.2
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL … wordfence
d559b862-ee07-4207-8c64-81961516a046
< 10.2.3
MEDIUM 6.4 The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URL values … wordfence
d5599101-a7bd-4aa7-91da-f11694bdc000
< 10.0.06
MEDIUM 6.4 The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp… wordfence
d54c7623-25af-4bf1-a6e0-9022ec26f391
< 2.6.4
MEDIUM 6.4 The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget Attri… wordfence
d54aed9a-d184-44e7-b1b6-465f288ca8de MEDIUM 6.4 The Get Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.6 du… wordfence
d4f60e8c-2745-4930-9101-914bd73c6e1c MEDIUM 6.4 The Horizontal scrolling announcement plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'horizontal-… wordfence
d4f4fbe3-44ec-4530-93e1-6422ed3ef188
< 0.2.5
MEDIUM 6.4 The Tainá theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.2.4 due … wordfence
d4f28285-bfa3-4063-bc8b-303db72d0156
< 2.5.39
MEDIUM 6.4 The Timely All-in-One Events Calendar plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters … wordfence
d4eb12ee-8c07-460d-8bfe-f2f78f7ed569 MEDIUM 6.4 The 6Storage Rentals plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includ… wordfence
d4e3e818-8d47-467a-b5cf-7eebd6a624a2
< 1.7.1
MEDIUM 6.4 The ThinkTwit WordPress plugin before 1.7.1 did not sanitise or escape its "Consumer key" setting before outputting it i… wordfence
d4dc2456-12fb-4f2c-a1e7-6cc5d1cf8faf
< 1.8
MEDIUM 6.4 The ANON::form embedded secure form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
d4d9e8fa-abc5-477a-bf99-dc910f0aabda
< 9.6.1
MEDIUM 6.4 The The Moneytizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9… wordfence
← Prev 522 523 524 525 526 527 528 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top