πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 550 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c0b86c45-c346-4df7-844e-01de027bbc1e
< 7.1.7
MEDIUM 6.4 The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wcj_pr… wordfence
c0b3911c-a960-4f28-b289-389b26282741
< 1.7.14
MEDIUM 6.4 The Drop Shadow Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dropshadowbox' shortcode in… wordfence
c098c975-3a9b-4b6c-81e7-c66ca9e3d09c MEDIUM 6.4 The Pure CSS Circle Progress bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cir… wordfence
c07a052d-5c04-48bc-82a7-4d50a5433290 MEDIUM 6.4 The News Kit Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
c07054e1-b6c9-4e70-aece-09f81bb418ef MEDIUM 6.4 The WP-PhotoNav plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's photonav shortcode in… wordfence
c0701e57-0771-48a2-ae1b-6429b27ce98f
< 2.11.0
MEDIUM 6.4 The TI WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
c06d7abc-c3dd-428f-b7dc-b2abc077435c
< 5.5.5
MEDIUM 6.4 The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
c064227f-6332-40c8-9e96-337c608da832 MEDIUM 6.4 The Mmm Simple File List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in… wordfence
c05687f4-5ea2-4226-982f-c3499f204685
< 2.0.51
MEDIUM 6.4 The Blocksy theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the custom_url parameter in all vers… wordfence
c05575ef-3140-4340-9b4b-1803a8045ce0
< 5.2.0
MEDIUM 6.4 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross… wordfence
c04d19fb-57b3-4361-bad3-eed98f693939
< 3.2.8
MEDIUM 6.4 The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
c04a0f82-97f6-44ff-999d-08a8c106f889
< 3.0
MEDIUM 6.4 The Pricing Tables For WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p… wordfence
c02a9639-525c-4e63-8ca0-2452667bbfd5
< 2.0.6.3
MEDIUM 6.4 The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
c0290595-d74d-404e-9d28-75abc9055031 MEDIUM 6.4 The EDD Download Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'edd_download_info_link'… wordfence
c028005d-f5cb-49e2-87d9-399b0d6530be MEDIUM 6.4 The Slider Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includ… wordfence
c01f7892-5ca2-4bc8-91c2-dfebb685aff8
< 6.4.8
MEDIUM 6.4 The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via DOM elements… wordfence
c01cbc25-bdf7-4525-8c7b-194bd0aeb32b
< 4.20.3
MEDIUM 6.4 The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.20.2 due t… wordfence
c017bd52-5548-4461-a6ab-336ab45a9e3e MEDIUM 6.4 The MLL Audio Player MP3 Ajax plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, a… wordfence
c00ff4bd-d846-4e3f-95ed-2a6430c47ebf
< 5.9.5
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
c00c735a-8c49-436b-9740-329b5c754712 MEDIUM 6.4 The drop in image slideshow gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
bff6fc62-9022-4a3b-9339-5b5d3205d671 MEDIUM 6.4 The Custom URL Shortener plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
bfc8c34c-3a1d-486e-96ca-ff50a1148813
< 4.2.6
MEDIUM 6.4 The Event Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
bfc4ab58-2117-42e7-b367-ee47e28c69ca
< 2.0.9
MEDIUM 6.4 The The Pack Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
bfba9979-44a2-4ad4-bb6a-f54f73b628d4
< 4.5
MEDIUM 6.4 The TP Education plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versio… wordfence
bfa62776-0502-49b4-8beb-74bbf7f20633
< 1.5.6
MEDIUM 6.4 The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
← Prev 547 548 549 550 551 552 553 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top