ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 531 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d01a7887-afd7-418b-99ad-92157582a506
< 0.2.1
MEDIUM 6.4 The FX Currency Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fxcc_conve… wordfence
d015e6ce-641c-4d68-b42b-03c039e973bd
< 1.3.4
MEDIUM 6.4 The Login with Vipps and MobilePay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'c… wordfence
d0117436-7a2a-42f3-8c05-75dfddfb9d09
< 5.5.0
MEDIUM 6.4 The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate wid… wordfence
d0059382-3e13-434a-a3d1-7892d14a371b
< 2.1.12
MEDIUM 6.4 The Html5 Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in … wordfence
CVE-2026-6646 MEDIUM 6.4 The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all v… nvd
CVE-2026-5070 MEDIUM 6.4 The Vantage theme for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery block text content in versions … nvd
CVE-2026-3534 MEDIUM 6.4 The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-c… nvd
CVE-2026-3034
< 2.1.25
MEDIUM 6.4 The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _ob_spacera… nvd
CVE-2026-2583 MEDIUM 6.4 The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `blocksy_meta` metadata fields in a… nvd
CVE-2026-2486 MEDIUM 6.4 The Master Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ma_el_bh_tabl… nvd
CVE-2026-2384 MEDIUM 6.4 The Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `vc_quizmaker` shortco… nvd
CVE-2026-2383 MEDIUM 6.4 The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field in all ve… nvd
CVE-2026-2367 MEDIUM 6.4 The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting… nvd
CVE-2026-2362
< 2.3.2
MEDIUM 6.4 The WP Accessibility plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'alt' attribute… nvd
CVE-2026-2029 MEDIUM 6.4 The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[labb_… nvd
CVE-2026-1941 MEDIUM 6.4 The WP Event Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_events' s… nvd
CVE-2026-1807 MEDIUM 6.4 The InteractiveCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… nvd
CVE-2026-1646 MEDIUM 6.4 The Advance Block Extend plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TitleColor block attr… nvd
CVE-2026-1373 MEDIUM 6.4 The Easy Author Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author_profile_picture_… nvd
CVE-2026-1236 MEDIUM 6.4 The Envira Gallery for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'justified_ga… nvd
CVE-2026-0556 MEDIUM 6.4 The XO Event Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xo_event_field… nvd
CVE-2026-0549
< 3.11.0
MEDIUM 6.4 The Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'groups_group_info' shortc… nvd
CVE-2025-6460 MEDIUM 6.4 The Display During Conditional Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘me… nvd
CVE-2025-14851 MEDIUM 6.4 The YaMaps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `yamap` shortcode par… nvd
CVE-2025-14445 MEDIUM 6.4 The Image Hotspot by DevVN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hotspot_content' c… nvd
← Prev 528 529 530 531 532 533 534 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top