🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 552 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
beb6b26a-3fe1-44e0-9fda-97b288abf735
< 4.4.2
MEDIUM 6.4 The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to … wordfence
beb28e9e-bf6a-4eed-afbc-ca85ec489df7
< 1.2.0
MEDIUM 6.4 The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_… wordfence
beb0eade-405b-429b-b7a5-0f9c09f8374e
< 1.8
MEDIUM 6.4 The Kattene plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.7 … wordfence
bea7a4d0-d589-420b-a4ff-eaccf12e623b
< 6.4.4
MEDIUM 6.4 The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File up… wordfence
be9e498b-acad-4909-87c0-e8693af15108
< 5.9.8
MEDIUM 6.4 The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.9.7… wordfence
be9d977d-d7b2-4946-b107-35df176fbdf3
< 3.11.8
MEDIUM 6.4 The Ultimate Post Kit Addons For Elementor – (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timelin… wordfence
be9abb15-f375-4dca-a998-e621d50fa273 MEDIUM 6.4 wordfence
be913494-f4a7-4718-ac2b-da4baf2b0a21 MEDIUM 6.4 The Meteor Slides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slide_url_value' parameter … wordfence
be88566d-fc84-442d-bb34-834ad9f4465b
< 3.13.0
MEDIUM 6.4 The Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF plugin for WordPress is vulnerable to Stored … wordfence
be860b7c-f0ac-4c28-8d7b-dc19f495476b
< 1.1.6
MEDIUM 6.4 The Realty by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
be83c6be-fb6c-462f-b54a-ca12d6d2581f
< 2.10.37
MEDIUM 6.4 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all… wordfence
be82095d-2b15-432e-a667-523286fa9629
< 3.1.1
MEDIUM 6.4 The Ziggeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ziggeo_event' shortcode i… wordfence
be7f8b73-801d-46e8-81c1-8bb0bb576700
< 1.8.5
MEDIUM 6.4 The Buzzsprout Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'buzzsprout' shortcode i… wordfence
be78b7d5-3f99-46de-b2b8-14254ee1ab71
< 3.2.7
MEDIUM 6.4 The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is v… wordfence
be71a324-2bf9-4257-947d-6998d59ad7cc MEDIUM 6.4 The CoDesigner WooCommerce Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… wordfence
be70f816-14b1-4c7b-8529-146bcd5d4cf3
< 1.2
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in the Terillion Reviews plugin before 1.2 for WordPress allows remote attacker… wordfence
be6c9176-6ace-4570-8b3c-2508d1937478 MEDIUM 6.4 The BU Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3… wordfence
be5eb703-8dcb-4e54-b81a-0c0e35dc29b0
< 2.0.2
MEDIUM 6.4 The Hyperlink Group Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tiptip/hyperlink-gr… wordfence
be51c54d-b0f7-42b2-b9b3-1b5832e10a6b MEDIUM 6.4 The XO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘get_slider’ function in all… wordfence
be4ce3e6-8baa-419f-a48e-4256c306fbc1
< 3.0.6
MEDIUM 6.4 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordi… wordfence
be4c0d73-9816-4e04-bcf8-a3be0488de7f MEDIUM 6.4 The CP Multi View Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
be4566c9-d003-4dc3-91f4-ff6cb6f1069a MEDIUM 6.4 The Lightweight and Responsive Youtube Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
be3c8800-cbef-4d85-a1f3-b5c70ba955b5
< 5.4
MEDIUM 6.4 The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
be398def-e887-4188-9a21-419f11b1a5b0
< 3.1.2.2
MEDIUM 6.4 The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all… wordfence
be1e0216-d9de-45e9-837c-0cccb78729a6 MEDIUM 6.4 The Display Medium Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_medi… wordfence
← Prev 549 550 551 552 553 554 555 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top