πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 530 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d0d9ba14-c0c9-426e-927e-9139a0882f0d
< 2.8.98
MEDIUM 6.4 The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable t… wordfence
d0d61395-3434-460f-8821-79e7676eff17
< 4.2.7
MEDIUM 6.4 The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to … wordfence
d0ca1d32-d094-46a2-838a-000e8b531767
< 1.1.3
MEDIUM 6.4 The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Coun… wordfence
d0c2f585-4bcd-43a4-a54a-7772caf63fa8 MEDIUM 6.4 The Piotnet Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
d0c0562f-1f3b-4630-bbc5-4ea2985d71d1
< 2.0.46
MEDIUM 6.4 The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file's name from a… wordfence
d0bf7032-aba0-429a-93b3-dd642147c7ec
< 2.4.3.1
MEDIUM 6.4 The JetBlog plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.3 du… wordfence
d0bd67c9-4c5a-41f0-971f-19e6525092ca
< 4.16.14
MEDIUM 6.4 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
d0bace1c-0a22-4f7f-9862-1eb0cd3ea48b MEDIUM 6.4 The Bitcoin Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
d0b73619-819a-49c3-a29c-549c6da2c523
< 0.90.3
MEDIUM 6.4 The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inc… wordfence
d0b3d83b-9695-40c5-b6ee-2a76c940de6e
< 5.4.1
MEDIUM 6.4 The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜_id’ at… wordfence
d0a60f4c-dc80-4ab6-8ce5-38eb9940c696
< 3.11.4
MEDIUM 6.4 The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cros… wordfence
d09a53cc-1773-467d-a9c7-72f343ed02a4
< 1.7.0
MEDIUM 6.4 The Mihdan: Elementor Yandex Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blo… wordfence
d0913632-85c5-4835-b606-4eca51df2496
< 3.2.24
MEDIUM 6.4 The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
d0864b6e-e193-4704-99ec-a5f2232c4816 MEDIUM 6.4 The Common Tools for Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all … wordfence
d07c43e0-783a-499b-b172-d058583d0749
< 1.5.143
MEDIUM 6.4 The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widge… wordfence
d077f0d4-24f6-454b-a05a-9df86a87a89c
< 2.2.0
MEDIUM 6.4 The WebberZone Snippetz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
d070f07a-c4e4-48ea-942d-7bb0bb834a52
< 2.2.87
MEDIUM 6.4 The ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several blocks in versions up to, … wordfence
d062fb5d-87ae-4a23-a8f7-d8e2c169db7e MEDIUM 6.4 The prettyPhoto plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.… wordfence
d058b578-3bf1-4bd4-a13b-8b55d4800fd9
< 1.2.2
MEDIUM 6.4 The OwnerRez plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.1 d… wordfence
d0467548-f1eb-4ea2-9913-4b7ffeb6e91a
< 2.1.7
MEDIUM 6.4 The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Basic Slider, U… wordfence
d03dbe48-371f-4fb7-8902-a013338ac7d4
< 1.9.0
MEDIUM 6.4 The The Permalinker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'permalink' short… wordfence
d03beb32-503c-4657-80d8-27800b2cb233 MEDIUM 6.4 The AgendaPress – Easily Publish Meeting Agendas and Programs on WordPress plugin for WordPress is vulnerable to Store… wordfence
d039ba8f-0452-4c14-a655-7f6880c1f1b4
< 3.4.24
MEDIUM 6.4 The My Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all v… wordfence
d034c3cb-8089-47d6-839b-659bedab5ca1
< 1.2.5
MEDIUM 6.4 The Contact Form By Mega Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
d01b6056-a38d-4a60-9cdc-68663aa2aed6
< 2.03
MEDIUM 6.4 The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STI Buttons shor… wordfence
← Prev 527 528 529 530 531 532 533 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top