ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 534 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ce8028a3-6fca-448f-b9a0-444db651148c MEDIUM 6.4 The Scalable Vector Graphics (SVG) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVGs in all ver… wordfence
ce7ee2c7-0c7b-4ce3-89d2-5503dff6e59c
< 2.1.31
MEDIUM 6.4 The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `blocksy_meta` metadata fields in a… wordfence
ce7c2f30-188a-4ae7-976f-c7f0aaf96eee
< 2.1.3
MEDIUM 6.4 The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's w… wordfence
ce5a89bc-c230-41d7-b0a7-d19d7b22ffb2
< 2.9.7.4
MEDIUM 6.4 The myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mycred_load_coupon' short… wordfence
ce57a3eb-a71b-4335-9e6c-52648ce00062 MEDIUM 6.4 The Allow SVG Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG uploads in versions up to,… wordfence
ce55230e-8c9e-41aa-b107-16c5988d1feb
< 2.7.21
MEDIUM 6.4 The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored… wordfence
ce3f1310-4d2e-45aa-a3ee-3972a6a31c2e
< 3.9.13
MEDIUM 6.4 The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gu… wordfence
ce3d82ec-5f94-4511-a6ba-8ee1dec06160
< 8.5.33
MEDIUM 6.4 The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to Stored Cros… wordfence
ce3861a3-3a0f-4414-bea7-941c2d36fc39
< 1.5.8
MEDIUM 6.4 The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
ce37fbd2-8d41-4feb-adf6-7ca0ca54e27a
< 3.10.9
MEDIUM 6.4 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
ce2d2594-e856-4249-9467-01c0fe1c0c71
< 6.2.2
MEDIUM 6.4 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vul… wordfence
ce27f598-b64a-45da-b61a-190570220ec2 MEDIUM 6.4 The Opal Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
ce182e57-a9d4-4c4b-b124-e6626ccdd712 MEDIUM 6.4 The Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ottwitter_feed' shortcode in… wordfence
ce116ee1-f0ea-469b-8c17-8c17c76fdc66
< 3.1.3
MEDIUM 6.4 The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content in all versio… wordfence
ce0757a2-8626-4f42-9854-da1dee289e13 MEDIUM 6.4 The Emma for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
cdeb9625-65fa-42bd-9708-7090691aae45 MEDIUM 6.4 The RRAddons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
cde79196-20aa-42f1-b35f-af347bcb6e5f
< 1.19.0
MEDIUM 6.4 The Flexible Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flexible Maps shortc… wordfence
cddda02e-c36f-4ed8-b3ac-6cb3f17c6ce2
< 1.7.14
MEDIUM 6.4 The CBX Bookmark & Favorite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
cdd7e9d1-a580-4b32-9365-7ce17cdc37cd MEDIUM 6.4 The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all v… wordfence
cdd7b2ec-5470-492d-a8ea-ae69b45572ce
< 8.6.1
MEDIUM 6.4 The NEX-Forms – Ultimate Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
cdd3d90a-6262-4dbe-b59b-593ca1a7dcaa
< 3.1.1
MEDIUM 6.4 The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
cdb69e0e-f3d4-4b5b-9bdf-14018f4c7ecc
< 5.6.6
MEDIUM 6.4 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… wordfence
cdb4cb5e-38ea-430e-b6ae-3712b3607a25
< 3.0.11
MEDIUM 6.4 The Domain For Sale plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class_name’ parameter… wordfence
cdaf96b6-1286-4bbc-893e-68de43ba1f25
< 1.1.20
MEDIUM 6.4 The SVG Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up … wordfence
cdaf1de1-9a84-469b-a7bb-694f80199cb7 MEDIUM 6.4 The Pdf Embedder Fay plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
← Prev 531 532 533 534 535 536 537 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top