🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 529 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d1c00b78-b525-4b6c-b232-7d24ef25c540
< 2.94.9
MEDIUM 6.4 The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to,… wordfence
d1bf83df-7a1f-4572-9c8d-1013750d51d7
< 3.7
MEDIUM 6.4 The Embed Calendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'calendly' shortcode in version… wordfence
d1a6345d-941f-4475-8b5f-d3cafed2ba73 MEDIUM 6.4 The Botnet Attack Blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i… wordfence
d19eeb42-2438-4126-8c60-14839baceff0 MEDIUM 6.4 The WPaudio MP3 Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) i… wordfence
d19a9c96-918f-4f19-82a9-badd5765cea3
< 3.2.6
MEDIUM 6.4 The Easy Digital Downloads plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
d1845942-2638-42db-9fdf-66890786ea0a
< 1.0.4
MEDIUM 6.4 The WP Pocket URLs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
d17aca2b-5ac6-46cd-a439-f492e6573a46
< 2.1.2
MEDIUM 6.4 The My IDX Home Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-idx-… wordfence
d1769ed5-5f56-4b70-af36-c60119f0a356
< 2.4.15
MEDIUM 6.4 The Five Star Restaurant Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
d175e862-64ea-4b7e-bf66-e1222efee6b6
< 1.1.9
MEDIUM 6.4 The Idyllic theme for WordPress is vulnerable to Stored Cross-Site Scripting via author display name in all versions up … wordfence
d15e36b6-61f9-42a4-86aa-8dd0e0563584 MEDIUM 6.4 The Menu In Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3… wordfence
d152271f-af5c-4faf-9945-483b69b716f2
< 1.6
MEDIUM 6.4 The Outdooractive Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'list2go' sho… wordfence
d11e8124-1028-4dba-bbd9-c45699d78909
< 2.6.4
MEDIUM 6.4 The Product Slider for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sh… wordfence
d11e3896-6901-4a52-b863-19cb25d21014 MEDIUM 6.4 The WooCommerce Coming Soon Product with Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
d116e432-ded9-4fc1-9509-710269dba5e0
< 3.5.2
MEDIUM 6.4 The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, whic… wordfence
d112f1b0-bfe0-44f0-b43a-334976bdb114
< 5.5.80
MEDIUM 6.4 The WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards plugin for WordPress is vulnerable to St… wordfence
d11295b5-0847-4c71-92fa-c35ba7fe7078
< 3.5
MEDIUM 6.4 The WEN Logo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
d11217ec-55a6-4422-9995-4cc1761d430e
< 2.2.0
MEDIUM 6.4 The Html Social share buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zm_sh_… wordfence
d108cb36-c072-483e-9746-15b8e7a880c3
< 2.6.3
MEDIUM 6.4 The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tag attributes in all v… wordfence
d106d581-d711-44ac-b85a-c43aad727eeb
< 1.1.10
MEDIUM 6.4 The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
d1040d5b-e02d-4762-825f-409c8770c66f
< 4.1.1
MEDIUM 6.4 The Zoner - Real Estate theme for WordPress is vulnerable to Multiple Cross-Site Scripting in versions up to, and includ… wordfence
d1010f1d-47d2-4aa9-9b31-e5d63dafbc39
< 4.2.4
MEDIUM 6.4 The WPFront User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
d10036de-940f-4772-9aca-13bc647548d2 MEDIUM 6.4 The Slider Pro Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sliderpro' short… wordfence
d0f6be2b-5eb6-4828-ae95-7f2253700ee9
< 2.10.44
MEDIUM 6.4 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ par… wordfence
d0ec9b5f-84c2-4736-98fb-130215430b8c
< 7.8.8
MEDIUM 6.4 The Link Library plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,… wordfence
d0e10c09-03b2-4286-95ef-e819fc2b900f MEDIUM 6.4 The Parabola theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.1 du… wordfence
← Prev 526 527 528 529 530 531 532 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top