🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 537 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cbde3644-4ac3-4082-9dc2-676c47c43532
< 8.6.9
MEDIUM 6.4 The Soledad theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.6.8 due… wordfence
cbd5dc98-ac5b-4548-9f98-faa91f5b1e2b
< 2.26
MEDIUM 6.4 The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, whi… wordfence
cbce42a0-29a7-40df-973c-1fe7338f6c94
< 1.23.11.6
MEDIUM 6.4 The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s… wordfence
cbcb1acb-1784-4ba2-83de-0fb89f5bd4d5
< 5.2.0
MEDIUM 6.4 The Da Reactions plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1… wordfence
cbca88e0-1563-43cb-adf4-4f89856a07d0
< 1.3
MEDIUM 6.4 The Dan's Embedder for Google Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'… wordfence
cbc3fa27-630d-4048-b727-903da09ad644
< 1.0.6
MEDIUM 6.4 The OneClick Chat to Order plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
cbc39f4e-6965-4c5e-b3e6-9ddecff0745b
< 3.3.1
MEDIUM 6.4 The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.3.1 due to insuffi… wordfence
cbc26607-a588-4059-9a37-afede7c9e3f6 MEDIUM 6.4 The Woocommerce – Products By Custom Tax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wo… wordfence
cbbbf5fe-0369-4de6-9b2f-957286b6f394
< 1.0.3
MEDIUM 6.4 The Koalendar – Events & Appointments Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
cbba866d-93dd-4ef5-9670-ab958f61f06e
< 3.3.3
MEDIUM 6.4 The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.… wordfence
cbb3bd9b-ac1f-4488-931f-2ba37576df2d
< 2.0.6
MEDIUM 6.4 The Futurio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘header_size’ attribute … wordfence
cbb3378a-d3e8-4a31-9ed2-f580960878cf
< 1.6
MEDIUM 6.4 The Divelogs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'latestdive' shor… wordfence
cba546d8-df3e-4ada-9cf9-663baf175dd0
< 1.6
MEDIUM 6.4 The Mikado Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and … wordfence
cb8ecbbc-ada9-4887-92e6-25a587ecfb84
< 7.6
MEDIUM 6.4 The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Author tag attribute in all … wordfence
cb823899-e90d-4857-9f72-aa7fe60aaca2 MEDIUM 6.4 The Jibu Pro plugin through 1.7 for WordPress is prone to Stored XSS via the wp-content/plugins/jibu-pro/quiz_action.php… wordfence
cb75b6ba-feb7-4e18-91f6-7ca1e90ef039
< 1.5.4
MEDIUM 6.4 The ImageLinks Interactive Image Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
cb725044-01c3-4c0c-b276-291f897f11e7 MEDIUM 6.4 The Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tweet_title' parameter in t… wordfence
cb6d11ad-0983-4a4b-b52b-824eae8b8e3c MEDIUM 6.4 The Google Maps Plugin by Intergeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'intergeo' shor… wordfence
cb64952e-170e-47c5-87fd-d2ec60192b65
< 1.1.40
MEDIUM 6.4 The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin f… wordfence
cb6457ea-6353-4a69-ad72-cd5acd47ed8c
< 15.0
MEDIUM 6.4 The Yoast SEO: Local plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
cb5ca73c-1a1d-4a93-bbcb-8af606189f26
< 1.1.6
MEDIUM 6.4 The B Carousel Block – Responsive Image and Content Carousel plugin for WordPress is vulnerable to Server-Side Request… wordfence
cb49f48e-98bf-4838-8eb0-91a7daad182c
< 2.3.85
MEDIUM 6.4 The GeoDirectory plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3… wordfence
cb472bdb-de35-45e4-bcea-04f27d425817 MEDIUM 6.4 The Wikiloops Track Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wikiloops… wordfence
cb46d7fa-9667-4479-8136-837cb61eaf4c MEDIUM 6.4 Anber Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $anber_item['button_link… wordfence
cb3f3bc7-9127-43ba-80ad-e32fd7c3b05e MEDIUM 6.4 The Essential Doo Components for Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… wordfence
← Prev 534 535 536 537 538 539 540 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top