πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 543 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c62ec31a-55e9-4404-b860-fa9a51ba3d3f
< 4.4.3
MEDIUM 6.4 The Essential Real Estate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ere_proper… wordfence
c62cb055-2816-40dc-b25b-395d7e230c9f
< 2.6
MEDIUM 6.4 wordfence
c62aa119-98bc-485e-92f2-43bf21756ebd
< 1.1.8
MEDIUM 6.4 The PowerBI Embed Reports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MO_API_POW… wordfence
c628dc0b-0648-4b7b-88cf-368771ebee45
< 8.1.6
MEDIUM 6.4 The Stylish Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
c6210c35-31d7-4a8d-b34f-596977c7a33e
< 1.2.20
MEDIUM 6.4 The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmcalendarview' sh… wordfence
c61b5726-6d54-4e1a-bf39-fb057bcd8c29 MEDIUM 6.4 The Simple Owl Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
c619e758-c71d-41cf-bff9-119ad9e3d9c4
< 2.2.90
MEDIUM 6.4 The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
c6109256-ac1d-43cf-b6e4-53aee4725483
< 1.1.0
MEDIUM 6.4 The Hello Event Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
c6102c07-2776-4963-8d16-a779c5979275
< 4.10.61
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Vide… wordfence
c6048ba9-671f-4729-9618-d7a0556a31e6
< 2.6.6
MEDIUM 6.4 The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sg_general_toggle_tab_en… wordfence
c6025dd5-a1d7-48cc-90b3-f020d3d2298b
< 1.4.4.4
MEDIUM 6.4 The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
c5fbb963-f89d-4037-9456-8587bcf5d620 MEDIUM 6.4 The Extra Post Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the ex… wordfence
c5f6ae5d-7854-44c7-9fb8-efaa6e850d59
< 3.11
MEDIUM 6.4 The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shor… wordfence
c5f24f89-3653-452d-bb1e-8bc113770624 MEDIUM 6.4 The WP Virtual Room Configurator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
c5ee2ae1-ea25-46fa-bc7c-114d4f6f9b4b
< 0.9.3
MEDIUM 6.4 The Progress Planner plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
c5e64adf-49b3-4e85-8dc1-918f7e92965b
< 2.6.20.1
MEDIUM 6.4 The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'slide_id' parameters… wordfence
c5c82d8d-88eb-4159-af94-3f8e257dded6
< 4.5.0
MEDIUM 6.4 The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
c5c2beb1-9478-487d-b11a-654e68ca9c3d
< 1.2.1
MEDIUM 6.4 The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
c5b8268a-f3a3-4576-b235-962de37cc388
< 4.4.0
MEDIUM 6.4 The Cision Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜id’ parameter in all ver… wordfence
c5b51ebf-4ae6-45b6-9eb3-dcfaeb8a06bd MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in preview-shortcode-external.php in the Shortcode Ninja plugin 1.4 and earlier… wordfence
c5a43f29-74d5-43ac-8c36-b4bc58942b9e MEDIUM 6.4 The PVN Auth Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all v… wordfence
c5a404de-ee26-44af-9e4f-f93694da7a77
< 1.7.1
MEDIUM 6.4 The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] plugin for WordPress is vulnerable to unauth… wordfence
c5960396-5320-4978-aa82-2e33700daa43
< 6.0.4
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
c59195f5-bb77-4f96-bd5e-b871d663ccce
< 2.9.3
MEDIUM 6.4 The Filter & Grids plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all v… wordfence
c581616d-c9e7-46f2-9c2f-5e082a13fd0b
< 1.2.4
MEDIUM 6.4 The WordPress prettyPhoto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜url’ parameter … wordfence
← Prev 540 541 542 543 544 545 546 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top