πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 568 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
afb3e68e-6f79-4c46-b41e-8fd6eb43c755
< 3.9.3.4
MEDIUM 6.4 The Knight Lab Timeline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) … wordfence
af9adb6b-f726-4b74-be5c-82fdab0ae1f2
< 3.10.0
MEDIUM 6.4 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
af9ad801-3c5c-4fb2-9fd7-a4eafae5012c MEDIUM 6.4 The Multi-Column Taxonomy List plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
af8bee01-15bc-485e-8b01-8b68b199b34d
< 5.9.9
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
af830ff1-5906-4765-a136-aef39caf7469
< 1.9
MEDIUM 6.4 The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ver… wordfence
af78ee37-17e8-4e03-a0dc-fc779e718e78
< 2.0.10
MEDIUM 6.4 The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ver… wordfence
af77d642-d383-48f2-a59a-3a9c738cd47f
< 6.3.2
MEDIUM 6.4 WordPress Core is vulnerable to Stored Cross-Site Scripting via the footnotes block in versions between 6.3 and 6.3.1 du… wordfence
af76e32b-ba7d-4eaa-97c8-ed6a25e8f387 MEDIUM 6.4 The Before After Image Slider WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shor… wordfence
af718d65-9f8f-4ed8-80ed-e7ed34169016 MEDIUM 6.4 The Easy Sign Up plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in version… wordfence
af7062ef-c8a8-4d3e-bc59-8451b2e89fb2 MEDIUM 6.4 The Wd-image-magnifier-xoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
af6c82e7-3161-47e6-b22e-c931d2126428 MEDIUM 6.4 The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
af650c7a-c413-4f4a-9e4b-8ddcd8da5397
< 5.5.0
MEDIUM 6.4 The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attribute… wordfence
af580e5a-a9da-4516-b612-b544dc73cf23
< 1.7.5
MEDIUM 6.4 The HT Slider for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slide_title' para… wordfence
af55ea6c-01f6-4c87-91bb-a0ff98e92256
< 4.1.16
MEDIUM 6.4 The PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.15 due… wordfence
af4f513e-5e28-429c-972c-7e1e4637916d MEDIUM 6.4 The Local Business Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
af478e73-a2b8-468a-9075-9c1db1a97d7c
< 9.6
MEDIUM 6.4 The MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions… wordfence
af39e563-5d88-460d-b02d-1aaa111c89dd
< 1.0.8
MEDIUM 6.4 The GamiPress – Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gamipress_b… wordfence
af29ec92-5b07-4f57-a25f-19f3a894a193
< 3.30.3
MEDIUM 6.4 The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
af181085-0a6b-4e87-b250-1fb4574d808d MEDIUM 6.4 The Bg Book Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `book_author` post meta,… wordfence
af12c836-a0ab-4d64-8921-61980edf47e7 MEDIUM 6.4 The Sell Digital Downloads plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
af0e3e7c-580c-4367-bda5-e94c1f7e8e65
< 9.6.5
MEDIUM 6.4 The XStore theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.6.4 due … wordfence
af053fdc-e40c-4dfa-8d16-09c72d839031
< 1.0.3
MEDIUM 6.4 The WP User Profile Avatar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(… wordfence
aef36e3c-90a0-4e88-8f36-13f56e9a5cec MEDIUM 6.4 The Author Box After Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
aee900ab-fbb4-461f-90a9-c01c8d1a5f35 MEDIUM 6.4 The LH QR Codes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.06… wordfence
aedde7a7-018d-45f9-8f67-f4ea01be894e
< 4.1.1
MEDIUM 6.4 The Cost of Goods: Product Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Stored Cross-S… wordfence
← Prev 565 566 567 568 569 570 571 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top