πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 536 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cca90146-83bb-42bd-9b3b-89298f7a2b2c
< 5.2.4
MEDIUM 6.4 The WP Flow Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.2… wordfence
cca7bb88-4a2c-4406-8610-15ce6e77c31f
< 1.3.976
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
cca6e588-0fd6-4643-897c-bcc3f482ddda
< 8.3.1
MEDIUM 6.4 The Stylish Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and exc… wordfence
cca53aba-b7dd-4b78-b2ac-c69050308e94 MEDIUM 6.4 The Runners Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'runnerslog' shortcod… wordfence
cc9e9238-7695-4ae1-83cb-8e321615a9b1 MEDIUM 6.4 The S3Player – WooCommerce & Elementor Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… wordfence
cc9d8d04-78af-4e43-8a51-89ece1d80336
< 1.94
MEDIUM 6.4 The Advanced Woo Labels – Product Labels for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
cc7bf6c6-22ad-49cc-8199-17825b1312e7 MEDIUM 6.4 The Business plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3 due… wordfence
cc751980-987f-49c5-a9fb-16ba219c174a
< 2.2.12
MEDIUM 6.4 The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPre… wordfence
cc6fdb7c-b750-4f03-9785-a9dc7573580d
< 5.5.5
MEDIUM 6.4 The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Hover Card w… wordfence
cc6ed7d3-7a57-4146-997b-96d4a9063214
< 4.9
MEDIUM 6.4 The Tagembed: Embed Twitter Feed, Google Reviews, YouTube Videos, TikTok, RSS Feed & More Social Media Feeds plugin for … wordfence
cc67fbfa-d84c-45c3-bbb1-4557dc70a8c9
< 3.8.4
MEDIUM 6.4 The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's brid_ov… wordfence
cc5f7a07-8117-4305-a72c-6afed80b6bcf
< 2.25.2
MEDIUM 6.4 The GiveWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'give_form_grid' shortcode in versi… wordfence
cc540e5c-180f-4743-b1fb-608aa0e3ae79
< 3.6.0
MEDIUM 6.4 The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-S… wordfence
cc4e17e5-25d3-4100-85a2-89f44fbd3834
< 5.0.24
MEDIUM 6.4 The Church Admin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0… wordfence
cc4d09e3-487a-4f12-818a-72ae9a6f33c0
< 3.9.9
MEDIUM 6.4 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all v… wordfence
cc4b52c6-1ac2-4f90-a776-c91232f5de34
< 1.0.4.1
MEDIUM 6.4 The WPBakery Visual Composer WHMCS Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl… wordfence
cc4a7efd-f4f4-44a7-bd55-a6ae3a1d3521
< 2.2.0
MEDIUM 6.4 The Perfmatters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in all versio… wordfence
cc3ab9de-4067-46db-99ee-e08cca4702c8
< 2.13.0
MEDIUM 6.4 The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
cc1ca9d4-49bf-4718-a451-edef8825a09c MEDIUM 6.4 The Bee Layer Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
cc1c76ee-078d-4c9a-a4d3-063d9147d7e8
< 1.6.4
MEDIUM 6.4 The Zita Elementor Site Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i… wordfence
cc10a78a-7950-4ebe-a8c2-a61156b60842
< 1.0.7
MEDIUM 6.4 The MT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
cc09377b-f30b-414b-a551-d3689ddcc5a4
< 1.8.3
MEDIUM 6.4 The Image Alt Text Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all v… wordfence
cc010feb-52bc-4775-a011-c0415cf5821c MEDIUM 6.4 The Show Google Analytics widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
cbee3d3b-383b-48f5-be63-61cd692a18a0
< 1.5.0
MEDIUM 6.4 The Simple Downloads List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
cbe0477e-4a48-4d0d-8cc4-17d1bce84658
< 1.1.27
MEDIUM 6.4 The Contact Form Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
← Prev 533 534 535 536 537 538 539 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top