πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 527 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d3905ebe-334c-4c6f-a430-4c25cd15c61f
< 3.5.1
MEDIUM 6.4 The Sina Extension for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
d38ee896-8cdd-45c5-b393-bdcb7baa7bd3
< 1.2.39
MEDIUM 6.4 The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
d385813e-960e-40ec-8b0f-8d2056a544c3 MEDIUM 6.4 The TC Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
d3804220-7c80-419c-9bf5-174e5c8ea924 MEDIUM 6.4 The Hotel Galaxy theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.4.… wordfence
d37bb136-c53d-4760-b7fd-91e6f20fbc20 MEDIUM 6.4 The Banner System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
d37599aa-d8e0-4ff2-8e15-a96f1865f4d9
< 1.0.17
MEDIUM 6.4 The X Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Youtube Video ID fi… wordfence
d359dc78-fc90-4570-a768-5f1a05f865e1
< 4.22.12
MEDIUM 6.4 The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
d3405b50-a3f0-4280-8a34-ed86ce3d4db4
< 3.1.1
MEDIUM 6.4 The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor… wordfence
d33fad22-7778-4407-9324-6edf7c333569 MEDIUM 6.4 The File Select Control For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
d33cc844-eaed-4006-aae1-122b773e9f11
< 2.0.7
MEDIUM 6.4 The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
d338b583-4587-4b8d-b78e-a1b9a1054435
< 1.3.3
MEDIUM 6.4 The WordPress Meta Data and Taxonomies Filter (MDTF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… wordfence
d337e39c-3a3d-4465-bc40-77f0b27aeab2
< 10.1.4
MEDIUM 6.4 The Import Spreadsheets from Microsoft Excel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p… wordfence
d33721e2-0a90-4102-84d5-2633c0fd47ed
< 1.0.23
MEDIUM 6.4 The AI Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aife_post_meta' shortcode in all… wordfence
d3364c9d-f814-4e48-a14b-50e7b02123f5
< 1.13.4
MEDIUM 6.4 The immonex Kickstart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
d32ceb67-8ad1-4f59-b4a8-63c9c3e8b90c
< 3.9.2
MEDIUM 6.4 The Visualizer plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, 3.9.1… wordfence
d31195f4-2e2f-41b8-9e8f-2264aa0bfc9e
< 2.0.0
MEDIUM 6.4 The Trip Plan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.10… wordfence
d311170c-db2b-4c23-aa43-98d7e92839bb
< 2.8.0.7
MEDIUM 6.4 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
d30d9b7e-86c0-4816-9362-ac363f61d5b7
< 3.2.22
MEDIUM 6.4 The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2… wordfence
d30cc136-ebde-4c76-9831-ffde79bf3c4a
< 7.2.1
MEDIUM 6.4 The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Server-Side Request Forgery in all v… wordfence
d3039831-6a29-48de-bdf3-66cac7655719
< 3.7.26
MEDIUM 6.4 Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a… wordfence
d2f777b6-5872-4196-81fb-82a9b6aaef2e
< 4.6.9
MEDIUM 6.4 The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up… wordfence
d2e60da7-25c6-44e9-aa62-ed32f0f5b0e0 MEDIUM 6.4 The WP krpano plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.1 … wordfence
d2d4a2ef-ea4a-456f-a8d1-600f51505ad7
< 45.12.0
MEDIUM 6.4 The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
d2d2954c-762c-4bdc-8469-7fe19f4e980d
< 3.1
MEDIUM 6.4 The web-cam plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜slug’ parameter in all versio… wordfence
d2cffdc3-bd74-42ab-befd-8a396c5d990d
< 6.2.0
MEDIUM 6.4 wordfence
← Prev 524 525 526 527 528 529 530 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top