🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 538 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cb3b8461-280e-41a3-bc26-32ef3897f184
< 1.3.1
MEDIUM 6.4 The Nelio Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3… wordfence
cb2c23cb-e7f6-4209-ab59-a44cd58d7d4c MEDIUM 6.4 The Elementary Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
cb2829eb-3079-429e-ab0f-e23a2c32d616
< 1.0.4
MEDIUM 6.4 The WP Post Disclaimer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the content disclaimer in v… wordfence
cb0ac434-7e85-44d4-b21e-df462f63cd9c
< 1.3.977
MEDIUM 6.4 The Royal Elementor Addons and Templates for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inline_li… wordfence
cb07f79f-6583-4f65-bc88-65dbd7207d5e MEDIUM 6.4 The SnapWidget Social Photo Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
cafc574d-2075-4e8c-8d9b-f0b2874a69bb
< 3.2.3
MEDIUM 6.4 The Tapfiliate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.2… wordfence
cad57b23-1d0a-4676-a52a-51ae0a13d126 MEDIUM 6.4 The Porn Videos Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
cad4c72d-9374-410a-91b7-5e9aff01738b
< 4.1.1
MEDIUM 6.4 The MainWP Boilerplate Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and inclu… wordfence
cac4608e-9eee-4e36-b219-a6133bac8a5f
< 2.1.28
MEDIUM 6.4 The Premium Blocks – Gutenberg Blocks for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
cac2a45e-f09e-4639-9a45-68d528a5094e
< 4.6.10
MEDIUM 6.4 The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco… wordfence
cac076c6-41b7-4daa-8703-2d6a2f01d02e
< 2.1.4
MEDIUM 6.4 The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
cabf776d-8749-45a8-94c1-7d1eef93a183
< 4.5.9
MEDIUM 6.4 The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data’ parameter in al… wordfence
cab56873-f79c-4fd2-8d40-ee4a338cbe8b
< 4.10.28
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's butt… wordfence
cab034fd-4cf2-4253-bbcd-c8bb86325fa8
< 2.0.6
MEDIUM 6.4 The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cro… wordfence
caa97ae8-40a8-4ca1-820b-83675c053bfc
< 3.9.11
MEDIUM 6.4 The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & El… wordfence
caa4aed4-0761-4ea6-841a-544a7f2ecb21
< 1.195
MEDIUM 6.4 The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
caa292cc-d907-4190-8d47-d311c7a19991 MEDIUM 6.4 The Popup Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.… wordfence
caa0f581-3fe8-4b9f-b69c-ec38ee25d697
< 5.1.2
MEDIUM 6.4 The SeedProd Coming Soon plugin before 5.1.2 for WordPress allows XSS. wordfence
ca9ad8ca-aad1-4950-b540-64ffc4a07c12
< 4.5.5
MEDIUM 6.4 The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions… wordfence
ca985d5d-56b9-4bf9-b51c-1d1a71c21a0d MEDIUM 6.4 The Woo Update Variations In Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up t… wordfence
ca803e6b-efbd-45e7-990d-d60d5d03fac5 MEDIUM 6.4 The MorningTime Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
ca7a968d-b1e9-4e8b-803a-58269910d9ff
< 4.4.3
MEDIUM 6.4 The UiChemy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.4.2 du… wordfence
ca74bb1d-1954-4869-aaa9-bf66600cdf2a
< 1.1.0
MEDIUM 6.4 The ThemeRuby Multi Authors – Assign Multiple Writers to Posts plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
ca686024-1479-48ed-8e21-4ebe3c981560
< 1.3.7
MEDIUM 6.4 The Time Slot plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.6 … wordfence
ca646202-b9e2-4272-b0e2-d39cd748fb8e
< 2.2.22
MEDIUM 6.4 The HTML5 Audio Player- Best WordPress Audio Player Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
← Prev 535 536 537 538 539 540 541 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top