🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 532 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2025-14142 MEDIUM 6.4 The Electric Enquiries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button' parameter of t… nvd
CVE-2025-14042 MEDIUM 6.4 The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via th… nvd
CVE-2025-14040 MEDIUM 6.4 The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via th… nvd
CVE-2025-13959 MEDIUM 6.4 The Filestack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'filepicker' shortcode … nvd
CVE-2025-13738
< 2.0.79
MEDIUM 6.4 The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ez-toc` s… nvd
CVE-2025-13617 MEDIUM 6.4 The Apollo13 Framework Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a13_alt_l… nvd
CVE-2025-13612 MEDIUM 6.4 The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… nvd
CVE-2025-12375 MEDIUM 6.4 The Printful Integration for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio… nvd
CVE-2025-12117 MEDIUM 6.4 The Renden theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, an… nvd
CVE-2025-12116 MEDIUM 6.4 The Drift theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and… nvd
CVE-2025-11737
< 9.112.4
MEDIUM 6.4 The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_sns… nvd
cff64b97-b3cf-41e7-aea6-004ab764e8e8
< 2.0.0
MEDIUM 6.4 The Magical Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
cff2e5be-0de0-4e62-a881-6156760b7d99
< 3.2.37
MEDIUM 6.4 The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-… wordfence
cfe548ce-5dc9-4073-b755-d28e37720808 MEDIUM 6.4 The GC Social Wall plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gc_social_wall' s… wordfence
cfdff272-fd65-4dfb-8b02-6d266ce4a1cc MEDIUM 6.4 The Provide Forex Signals plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
cfcd59ae-085f-47d2-a4d2-2d1239f035d2
< 4.5.4
MEDIUM 6.4 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Store… wordfence
cfaa8ffd-549e-4803-aa17-d1317a606e7a
< 3.3.3
MEDIUM 6.4 The Sky Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sky-custom-scripts` custom pos… wordfence
cf810967-9fb9-4d6b-9671-1f41176248bb
< 7.0.1
MEDIUM 6.4 The Ecwid Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
cf7c3ffe-079e-4db4-9dc4-3405527c0a99
< 3.0
MEDIUM 6.4 The Image Over Image For WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
cf7adeb3-4c6b-4181-af07-0acb1fc8cdb0 MEDIUM 6.4 The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attr… wordfence
cf7987ed-bde8-41a1-b679-299e7b09e282
< 9.0.13
MEDIUM 6.4 The teachPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.0.1… wordfence
cf6e3552-9616-4da1-8d8e-a6144ba1d0a3
< 1.1.11
MEDIUM 6.4 The Easy PayPal Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortco… wordfence
cf6c13de-e666-4c80-aa4c-6f610d899d03
< 3.19.0
MEDIUM 6.4 The Flatsome theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versi… wordfence
cf68401a-0a79-43f0-adee-fd0594d5dee0
< 4.7.0
MEDIUM 6.4 The PDF Invoices for WooCommerce + Drag and Drop Template Builder plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
cf665438-20d2-4df9-b3ff-54123343a46d
< 3.2.2
MEDIUM 6.4 The Rencontre – Dating Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘facebook’ p… wordfence
← Prev 529 530 531 532 533 534 535 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top