🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 526 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d4d5ae93-000e-4001-adfa-c11058032469
< 4.5.4
MEDIUM 6.4 The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the featured im… wordfence
d4d11477-8a9a-42a0-aafd-5ef10ca5a349
< 1.13.3
MEDIUM 6.4 The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in version… wordfence
d4c56931-c2af-4940-95e4-3f3dae51c31c MEDIUM 6.4 The Collapse-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'expand' and 'ex… wordfence
d4c1add9-2141-4221-889b-f9b0efebd6c7
< 1.4.7
MEDIUM 6.4 The Activello plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4… wordfence
d4b06b93-6b15-4b1f-bdd9-080618591bdc
< 5.7.2
MEDIUM 6.4 The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Se… wordfence
d4aa9303-953f-4bc3-8069-8e9a967461a9 MEDIUM 6.4 The Jeba Cute forkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' parameter in the '… wordfence
d4933a30-974f-487d-9444-b0ea1283a09c
< 2.10.4
MEDIUM 6.4 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Cus… wordfence
d4664b8d-4f8f-4be3-90e9-2dba4e737b2c MEDIUM 6.4 The Smart Logo Showcase Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod… wordfence
d4634b17-923d-4000-9881-d1c2d235f039 MEDIUM 6.4 The DataMentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7 d… wordfence
d45a4b0b-bb98-4c35-a743-c434946002a2
< 1.0.3
MEDIUM 6.4 The Responsive Lightbox2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hyperlink’ attri… wordfence
d44ecf8a-d19a-403a-96c7-89e223a5cc22
< 2.6.9.1
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Covid-19 St… wordfence
d449466d-e78a-48a3-8eff-90b56646dd6b
< 5.12.7
MEDIUM 6.4 The Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) … wordfence
d4429eb0-2b9a-4366-9f93-90484872c48e
< 4.0.27
MEDIUM 6.4 The Church Admin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all … wordfence
d402b7d1-3c12-4bdd-8ff3-e58d5501f0c0
< 5.2.2
MEDIUM 6.4 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress … wordfence
d4027138-9a8a-4602-90fd-19e9f7c45bb4
< 3.3.2
MEDIUM 6.4 The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-… wordfence
d3e293db-9177-4fbb-a469-900d9330642d MEDIUM 6.4 The Columns by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attr… wordfence
d3dfa92a-57da-49ab-95f7-504fa99ed47f
< 4.12.0
MEDIUM 6.4 The oik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bw_button shortcode in all ve… wordfence
d3dae870-9b5f-47ef-b8b2-23fac613ec00 MEDIUM 6.4 The i2 Pros & Cons is vulnerable to stored Cross-Site Scripting in versions up to, and including, 1.3.1, via the 'i2_pro… wordfence
d3c2e5fe-cc02-479e-9f33-e1a783088596
< 8.5.1
MEDIUM 6.4 The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘piechart_s… wordfence
d3c1d9ba-a736-4fb9-bdd3-6dc79881baf8 MEDIUM 6.4 The Content Fetcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
d3bea017-9fc3-4e14-97c4-5bb525650cde
< 7.2.8
MEDIUM 6.4 The WPC Composite Products for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wo… wordfence
d3bb5bb0-2c70-4416-8ee1-97aba100cc1d
< 1.2.2
MEDIUM 6.4 The Themify Portfolio Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(… wordfence
d3b9d0ab-d785-4e93-9ab8-f75673a27334
< 4.15.2
MEDIUM 6.4 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
d3b26060-294e-4d4c-9295-0b08f533d5c4
< 2.2
MEDIUM 6.4 The Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tmfshortcode' shor… wordfence
d3ab23ea-5ded-49dc-9d03-6d1773947d56
< 1.0.6
MEDIUM 6.4 The Anant Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
← Prev 523 524 525 526 527 528 529 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top