🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 535 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cda6d5d5-b49a-40f4-9c83-c1c569891339
< 2.3.1
MEDIUM 6.4 The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stor… wordfence
cd7ed687-4049-4957-86e9-b2f59621c747
< 1.3.3
MEDIUM 6.4 The Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'testimonialcategory' s… wordfence
cd7875d6-e866-4625-94e5-2ef8a1d11503 MEDIUM 6.4 The GMap Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘h’ parameter in all ve… wordfence
cd6f4f0d-0e70-459a-8f09-64d1f6f8bb7e
< 1.3.9
MEDIUM 6.4 The BuddyForms ACF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions … wordfence
cd6ed285-f215-44d3-9db9-9b2bfffee60a
< 2.8.1.3
MEDIUM 6.4 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
cd600810-b1bc-4025-b441-5c90da7240de
< 1.6.4
MEDIUM 6.4 The Tune Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via CSV import in all versions up to,… wordfence
cd59bee7-5de5-406d-8c1b-654306d68ab8
< 3.9.10
MEDIUM 6.4 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
cd3fe254-e8cb-450b-901b-fdf49209013f MEDIUM 6.4 The Testimonial Post type plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ para… wordfence
cd2dfa02-0404-4300-a5ed-6326f9df6d30
< 3.1.3
MEDIUM 6.4 The TablePress plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the 'data-caption', 'data… wordfence
cd2abab4-f93c-454d-928d-128a490da0e2 MEDIUM 6.4 The Gumroad plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.0 du… wordfence
cd1cf741-9a24-40be-9b7f-ffaa9d1d4808 MEDIUM 6.4 The Today's Date Inserter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
cd190651-2a82-41b2-9c59-5ae6e4441220 MEDIUM 6.4 The Follow Us Badges plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
cd126bcb-0add-4662-a4d9-03a55a7d9a32
< 1.3.4
MEDIUM 6.4 The “Image Hover Effects – Elementor Addon” WordPress Plugin before 1.3.4 has a widget that is vulnerable to store… wordfence
cd066a04-8094-4004-8a64-317c6bd4e101 MEDIUM 6.4 The WP Font Awesome Share Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp… wordfence
cd016800-ad9b-4617-82ff-1c439b9b3920
< 3.3.1
MEDIUM 6.4 The Scriptless Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
ccfd4949-07ae-48b6-9aa2-82fd6b1bf692 MEDIUM 6.4 The Flexi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin for WordPress's flexi-form-ta… wordfence
ccf4554e-4b34-46b0-b423-5cee7150e6c2
< 1.29
MEDIUM 6.4 The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery… wordfence
ccf0d482-b4a1-47a8-8741-0970531e9630
< 4.5.2
MEDIUM 6.4 The Companion Sitemap Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shor… wordfence
cce4d44a-4613-4230-ace1-2d26c7c487b3
< 4.0.2
MEDIUM 6.4 The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
cce35f0b-07b2-4b7b-b1c9-fcf2840e8437
< 40.1
MEDIUM 6.4 The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Server-Si… wordfence
ccd917ae-3fa2-47b5-ace7-1462647e2352 MEDIUM 6.4 The WP Baidu Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'baidu_map' shortcod… wordfence
ccd273dc-9de3-4863-a787-db653f2003ca MEDIUM 6.4 The DPEPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dpe' shortcode in all v… wordfence
ccd11b05-feb0-4e32-b11d-9c8f10ddf30a
< 1.0.7
MEDIUM 6.4 The Affiliate Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘numColumns’ paramet… wordfence
ccb7e94c-385e-4ce9-acfa-978403047159
< 4.10.25
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Coun… wordfence
ccb6275e-d933-428c-890c-dbfb95d5e4a1
< 2.1.4.9
MEDIUM 6.4 The WP Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘facebook_page_shortcode’ fu… wordfence
← Prev 532 533 534 535 536 537 538 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top