πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 551 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bfa12bf7-5056-4d65-885c-36fcb37c017c
< 1.3.9.3
MEDIUM 6.4 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
bfa03994-3a5a-4e8f-91e4-5564afa76559 MEDIUM 6.4 The Terms Before Download plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
bf7b0f1b-a6d3-4a96-adaa-0adeb6ea2efd
< 7.1.3
MEDIUM 6.4 The WP Shortcodes Plugin β€” Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
bf68dec8-9cb9-4eff-9c1a-4c227de30cf2 MEDIUM 6.4 The YouTube Simple Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
bf682127-4b97-44ce-a94d-3a237c5af1cc
< 1.7
MEDIUM 6.4 The Admire Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'space' shortcode in… wordfence
bf5fe4c5-0a18-4efb-b492-fad2ae3ca3da
< 1.6
MEDIUM 6.4 wordfence
bf5e2ff9-a293-4e42-8e43-b3a347cdfe6e
< 1.5.4.2
MEDIUM 6.4 The JetTricks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.4.… wordfence
bf5904b4-a2a5-4cbc-9e38-b41459cedb45
< 5.1.1
MEDIUM 6.4 The Trackserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1.… wordfence
bf4dcdab-6c74-4c0e-bdda-67e60025a873
< 2.1.17
MEDIUM 6.4 The WP Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up… wordfence
bf464e16-f5cf-4b3e-a9ee-b3df9aa38c9e
< 2.8
MEDIUM 6.4 The Product Slider and Carousel with Category for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
bf41b5e1-610e-4159-9325-f7a694380050
< 2.4.2
MEDIUM 6.4 The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress … wordfence
bf3c6dd5-498e-4aff-90fb-15ede66f5e3e MEDIUM 6.4 The WP Tournament Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜field’ par… wordfence
bf332c0d-5481-412d-b44a-b3de346d7b60
< 1.0.8
MEDIUM 6.4 The Smart Appointment & Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the saab_save_form… wordfence
bf214d08-0079-40f2-8beb-6f5e4953bb95
< 1.3.6
MEDIUM 6.4 The Black Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
bf20b6c2-6c6a-4feb-9d52-87b7f214f1f7
< 1.2.2
MEDIUM 6.4 The List Last Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
bf173ccd-23bc-49ec-92e0-032feae0fa4a MEDIUM 6.4 The Candifly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'candifly' shortcode in … wordfence
bf169c9c-26f6-4af7-926e-1be34e638fd6
< 1.1.3
MEDIUM 6.4 The WP Mail Log plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capabilit… wordfence
bef34ef0-ce0a-46af-9bc2-228dd5e80717
< 1.7.12
MEDIUM 6.4 The Cookie Notice & Consent Banner for GDPR & CCPA Compliance plugin for WordPress is vulnerable to Stored Cross… wordfence
beeb129e-1838-4f2b-b936-06f7c26ee587
< 2.8.0
MEDIUM 6.4 The The Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 2.8.0 due to insufficie… wordfence
beea6ca0-5982-436e-959e-6761f05d4675
< 4.0
MEDIUM 6.4 The GD bbPress Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
bee2d981-c6b4-4f2b-af4e-90e997257743 MEDIUM 6.4 The Posts Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3… wordfence
bedc2254-29aa-46c5-8f85-47dd6affb42b
< 3.13.12
MEDIUM 6.4 The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
bedbe508-e879-4989-89a6-db909ecd35a8
< 5.0.20
MEDIUM 6.4 The Brandfolder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜id’ parameter in all vers… wordfence
bedad627-0ccb-41c1-be8d-753f57be618f
< 5.9.21
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugins for WordPr… wordfence
bebedaa9-6689-4863-91c6-2ab52a9353db
< 2.2.4
MEDIUM 6.4 The WP Social Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in ve… wordfence
← Prev 548 549 550 551 552 553 554 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top