🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 533 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cf64f1c5-257d-49b2-b626-eaa4592b8335 MEDIUM 6.4 The scratchblocks for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' attribute o… wordfence
cf558c77-fc78-4149-bc7f-2b5353144daf MEDIUM 6.4 The YouTube Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘instance’ parameter in … wordfence
cf37013e-872a-4582-b6b2-4335f2d9c818 MEDIUM 6.4 The Store Commerce theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
cf238735-8c21-495b-8da0-912921c1f11c
< 1.5.0
MEDIUM 6.4 The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.3 … wordfence
cf195cca-4e07-41ff-bf26-9ad5fca3635d
< 3.0.7
MEDIUM 6.4 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button ID par… wordfence
cf17a817-6f61-43d5-9da2-58fbbef458d9
< 1.2.10
MEDIUM 6.4 The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fcb shortcode in versio… wordfence
cf1000eb-fac3-4710-bfcd-a6cc2c6327d4
< 2.2.1
MEDIUM 6.4 The Aparat for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
cf0950d3-4d7b-457a-8e67-df310d2712d4 MEDIUM 6.4 The AMO Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's amoteam_skills … wordfence
cf001185-8ecc-444d-a4f7-3d9b3267be35
< 1.6.3
MEDIUM 6.4 The Related Products Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
ceebd61a-a7f8-4854-8b54-b61f8bf204e6 MEDIUM 6.4 The Raptor Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
ceeae3e8-d213-4770-b8cb-67e4cdbbe89a MEDIUM 6.4 The Magic Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3… wordfence
ceda1e49-4e65-4038-9207-ef4647838f53 MEDIUM 6.4 The Inline frame – Iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedsite' shortc… wordfence
ced6450a-7d5a-4091-8181-98c005e74346
< 3.3.3
MEDIUM 6.4 The Mantra theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.2 due … wordfence
ced350cf-1116-4003-ac74-f6dec34360a5
< 13.4.2
MEDIUM 6.4 The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
cecf47b8-acda-4a9f-9cf4-e25626d63c26
< 1.6.3
MEDIUM 6.4 The Analytics Germanized for Google Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
cec428cd-0fa1-4bc4-b7f6-faf90c31f306 MEDIUM 6.4 The Menu Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `category` parameter in all vers… wordfence
cebe27ca-ab29-48dd-bb3c-bcbe8573889b
< 3.11.2
MEDIUM 6.4 The Master Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.… wordfence
cebd40c2-42df-4792-81dc-2b1082f1712b
< 4.14.2
MEDIUM 6.4 The WordPress Real Media Library WordPress plugin is vulnerable to Stored Cross-Site Scripting via the name parameter in… wordfence
ceb7316e-8b55-4e7a-9309-8a9e84f22c90
< 1.4.1
MEDIUM 6.4 The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'row' shor… wordfence
ceb041f6-b88a-495a-8f5f-7f39f640748d
< 2.6.10
MEDIUM 6.4 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sto… wordfence
ceae0115-268c-401b-876b-3477d10c10e6
< 3.9.6
MEDIUM 6.4 The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & El… wordfence
ceaa3a5a-c64c-402f-b4f9-33a9577a41ec MEDIUM 6.4 The Abbie Expander plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
ce9e5b74-dc20-4bb8-884e-bf46d2a484c1 MEDIUM 6.4 The Buckets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.3.9 du… wordfence
ce9b908b-1388-41fb-915c-e4e29eaf57ed MEDIUM 6.4 The Magic Action Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to,… wordfence
ce88d6e9-b35a-4099-bd6f-d09eac0c8170
< 1.4.0
MEDIUM 6.4 The Appointment Booking Plugin for WooCommerce | Online Booking Calendar & Service Manager plugin for WordPress is vulne… wordfence
← Prev 530 531 532 533 534 535 536 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top