πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 553 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
be0c29a3-0b78-4259-a514-c3674d9d5d55
< 3.3.5
MEDIUM 6.4 The DWT - Directory & Listing WordPress Theme is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up… wordfence
be054481-89b4-47d8-ad06-8622edea367f
< 1.2.0
MEDIUM 6.4 The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
be004002-a3ac-46e9-b0c1-258f05f97b2a MEDIUM 6.4 The QR Code Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'qrcodetag' shortcode in versions … wordfence
bdf00861-e31e-485c-a562-12dba56af1c7
< 1.3.0
MEDIUM 6.4 The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all ve… wordfence
bded6765-e994-46a4-8c88-c324a4fd6ee6
< 3.0.4
MEDIUM 6.4 The Perfect Portal Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'perfect_p… wordfence
bdebb4a6-1bf8-4a61-b690-cf933215216a
< 2.16.5
MEDIUM 6.4 The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Comparison, … wordfence
bde3ef64-ee36-464c-affc-95d904575499
< 1.4.10
MEDIUM 6.4 The The Events Calendar Countdown Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
bde0aef3-aa61-4ee7-9cbf-9f51cb5ac700
< 3.1.17
MEDIUM 6.4 The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ext… wordfence
bdde01aa-2d38-4085-b11a-ef8633ee928a MEDIUM 6.4 The Tournament Bracket Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bra… wordfence
bdd4022f-b038-4351-9798-77e7c24f1173
< 1.3.979
MEDIUM 6.4 The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
bdd0ba4b-56f1-4f4b-95f7-28c911c8de09
< 4.16.4
MEDIUM 6.4 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
bdd07160-721b-4807-a227-72cd91faef39 MEDIUM 6.4 The States Map US plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'states_map' shortc… wordfence
bdceb07a-87d2-4708-b76b-5a8fcfff0818
< 3.3.59
MEDIUM 6.4 The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
bdcb0402-1489-441b-a2ba-51c79e0328db
< 1.9
MEDIUM 6.4 The Tab Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8… wordfence
bdcab7d4-90c5-499f-85aa-91f08a1020a4
< 4.21.8
MEDIUM 6.4 The Leaky Paywall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… wordfence
bdc6db8e-9d26-4bfb-9f76-6273eaf79609
< 5.10.5.1
MEDIUM 6.4 The TheGem (Elementor) theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
bdb619c5-967c-4b8c-8a93-bcdb49137d56
< 1.2.61
MEDIUM 6.4 The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. Th… wordfence
bdaf7575-0f72-4436-8a37-b3001890b710
< 1.9.8
MEDIUM 6.4 The Compact WP Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions … wordfence
bda249f7-07a9-47ba-bba4-85abd8f8a207 MEDIUM 6.4 The elink – Embed Content plugin for WordPress is vulnerable to Malicious Redirect in all versions up to, and includin… wordfence
bda01b23-1759-433a-971d-73b8458ad9ce
< 2.6.1
MEDIUM 6.4 The Responsive Flickr Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
bd9b77fa-6de5-493e-978a-9957f44e32a1
< 2.0
MEDIUM 6.4 The Sitekit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9 due … wordfence
bd933aa8-756f-460f-8d83-a626a6ed43b1
< 4.2.4
MEDIUM 6.4 The Loops & Logic plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… wordfence
bd90b85e-22a9-4c08-b2cf-4f75406e7ca3
< 1.7.1002
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
bd8fbe0d-0709-4fa2-9294-393ddcd05b22
< 3.9.1
MEDIUM 6.4 The Webling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.9.… wordfence
bd8a61d1-904d-4027-8f27-6e3018862d9b
< 2.1.1.3
MEDIUM 6.4 The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Sc… wordfence
← Prev 550 551 552 553 554 555 556 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top