πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 555 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bc552d46-79ca-4540-8620-5a031238cd62
< 1.12.4
MEDIUM 6.4 The Envira Gallery for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'justified_ga… wordfence
bc51ccec-558c-4155-a309-badf99202ce1
< 3.35.6
MEDIUM 6.4 The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
bc425c4a-cb4e-4f50-b85b-8c4c7778c073
< 3.0.98
MEDIUM 6.4 The Magic Conversation For Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'magi… wordfence
bc3910e4-649f-45ab-876a-a4b04afac8d2
< 7.6
MEDIUM 6.4 The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SEO title and des… wordfence
bc22a8df-44be-477e-a3b6-67960bf442d3
< 4.1
MEDIUM 6.4 The Easy Social Like Box – Popup – Sidebar Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
bc121ed0-4cb3-4ba4-b693-413b1c25e4ca
< 6.5
MEDIUM 6.4 The Weaver Xtreme Theme Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's div s… wordfence
bc0d36f8-6569-49a1-b722-5cf57c4bb32a
< 5.9.10
MEDIUM 6.4 WordPress Core is vulnerable to Stored Cross-Site Scripting via the HTML API in various versions prior to 6.5.5 due to i… wordfence
bbe92b43-ae83-408b-962d-4867d032e8dc
< 2.4.3
MEDIUM 6.4 The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to Stored Cros… wordfence
bbe87391-735a-48e3-be7f-024644c35e8c MEDIUM 6.4 The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
bbe7beae-2803-463c-83ad-5a58c4a55a65 MEDIUM 6.4 The Credits Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the … wordfence
bbda67a3-0413-4d8e-8157-84c9c87b8695
< 4.2.1
MEDIUM 6.4 The Zakra theme for WordPress is vulnerable to Stored Cross-Site Scripting via post meta values in all versions up to, a… wordfence
bbd7dcff-8a9f-40bd-b350-ad8dd7a85574
< 14.10
MEDIUM 6.4 The Latest Post Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
bbbb41de-8853-41d1-8801-1eb86867e4ba
< 3.1.1
MEDIUM 6.4 The Product Notes Tab & Private Admin Notes for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
bbb9483b-ee00-4e40-8fa3-eefbbfeb9516
< 3.2
MEDIUM 6.4 The UpMenu – Online ordering for restaurants plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
bbb47f29-7a70-462d-913c-7af9c7b8709a
< 7.5
MEDIUM 6.4 The Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
bbb3ee94-e631-47ee-9f16-6bf7c23abab1
< 3.13.2
MEDIUM 6.4 The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tit… wordfence
bba90659-09a8-470a-91d3-d1986562672a
< 1.9.14
MEDIUM 6.4 The Compact WP Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_embe… wordfence
bba3eeeb-5e7e-4ec3-9db0-02c44585647a
< 4.1.38
MEDIUM 6.4 WordPress Core is vulnerable to stored Cross-Site Scripting in versions up to, and including, 6.2, due to insufficient v… wordfence
bba2eb67-70a9-438b-8d18-774fcf557469 MEDIUM 6.4 The azurecurve Toggle Show/Hide plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
bba19523-8b8e-4e91-b16b-8c9d5c410efa MEDIUM 6.4 The FW Anker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.6 d… wordfence
bb9bce29-9842-4d8a-ac9b-24432a28851c MEDIUM 6.4 The Opening Hours plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in ver… wordfence
bb991940-b4ed-4b64-be59-afe37eaf3a2c MEDIUM 6.4 The Planning Center Online Giving plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho… wordfence
bb93853b-a6e0-42d1-8b10-b391984603f2
< 3.10.5
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Calend… wordfence
bb74a917-2dfb-4229-a72a-9c3d1f9a6324
< 1.0.8
MEDIUM 6.4 The GamiPress – Youtube integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
bb5e6ff6-e70c-4b46-80fc-498becca6158 MEDIUM 6.4 The GWP-Histats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 … wordfence
← Prev 552 553 554 555 556 557 558 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top