🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 557 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ba7f7c7e-9779-4bd1-9412-dc0c81f4872c
< 1.22.8
MEDIUM 6.4 The WP Frontend Admin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
ba7b8fe5-aa49-4a70-89c9-1b95a30b1142
< 1.7.1057
MEDIUM 6.4 The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the I… wordfence
ba751f98-f86c-451b-8a12-a2e9e76768e5
< 6.20.3
MEDIUM 6.4 The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for Wor… wordfence
ba747152-d6a0-4bf5-a321-ede24490594a
< 3.9.3
MEDIUM 6.4 The WP Travel Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
ba6e897e-8f6a-418a-98ec-7bb645aa2630 MEDIUM 6.4 The SOCIAL.NINJA plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.2… wordfence
ba67cfbc-8bdf-4ca1-acee-0d1bb0348c60
< 153
MEDIUM 6.4 The Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management plugin for WordPress is vulnerable to… wordfence
ba56821e-7557-4bf8-b41f-b5240a1f5789
< 2.2.4
MEDIUM 6.4 The WPAdverts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.3 … wordfence
ba551103-f373-40b0-831f-a1c59bb874ca
< 2.2.1
MEDIUM 6.4 The YaySMTP – Simple WP SMTP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'settings[… wordfence
ba4ab6fc-340c-442b-9b8e-b5534fd9c3be MEDIUM 6.4 The Product GTIN (EAN, UPC, ISBN) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
b9f8c600-d62d-4f27-ba73-1a77a63859bc
< 2.7.6
MEDIUM 6.4 The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Server-Side… wordfence
b9f34195-fc03-4c3d-b25e-c9b9cf8ded3c
< 3.7
MEDIUM 6.4 The Shopkeeper Extender plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'image_slide'… wordfence
b9e998fd-aae7-4e1e-8134-a28670a4704b
< 1.0.14
MEDIUM 6.4 The Checkout for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes ('item_descript… wordfence
b9e3e417-d8a8-4e32-99aa-650e0a25a415 MEDIUM 6.4 The Top 25 Social Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in … wordfence
b9e0e5bd-d87e-48bd-8ee2-9c1cf63632c6 MEDIUM 6.4 The Musician's Pack for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
b9da31ff-4173-4aee-a3a6-8eebaa0d71ab
< 2.5.1
MEDIUM 6.4 The WP Multi Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(… wordfence
b9d96ebe-fc20-4b0e-bba2-4853459cf74e
< 3.3.7
MEDIUM 6.4 The Ali2Woo Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3… wordfence
b9d77b08-3a4a-441b-8725-fd93744de73c MEDIUM 6.4 The Etsy Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'product_link' shor… wordfence
b9d39796-ad51-4b52-af8a-f3334e6ca68d
< 5.7
MEDIUM 6.4 The Page-list plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.6 du… wordfence
b9cf68a4-0c0c-4b1b-82da-1df8c6ebb30d
< 7.3.1.3
MEDIUM 6.4 The Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7… wordfence
b9985992-e64c-4292-9738-cd38fb44a6f0 MEDIUM 6.4 The Dexs PM System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subject’ parameter in … wordfence
b9909373-48d7-425b-a20b-bb8bf2a80e9b MEDIUM 6.4 The Preload Current Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'complete' paramete… wordfence
b987822d-2b1b-4f79-988b-4bd731864b63 MEDIUM 6.4 The WordPress Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wordpress_social_l… wordfence
b97a555a-1eeb-4fc4-9338-bad8b9a0585d MEDIUM 6.4 The F4 Improvements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio… wordfence
b978fbe2-ac89-4054-96bc-1f3d452170d9
< 1.3.14
MEDIUM 6.4 The UiCore Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
b973f244-37eb-4e60-ae02-ddca3e988af1 MEDIUM 6.4 The Fusion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.3 due… wordfence
← Prev 554 555 556 557 558 559 560 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top