πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 569 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
aeda43bc-eeee-463d-80b7-dec7975b4d19
< 1.51.1
MEDIUM 6.4 The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜zone’ parameter in all ve… wordfence
aeb57757-9f48-43cc-a8a8-787f0af1974c MEDIUM 6.4 The Poll Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3… wordfence
aeada6dc-0851-45e8-ada9-ff0427b7f17a
< 1.3.1
MEDIUM 6.4 The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block at… wordfence
ae9ff893-9a56-4e3b-805a-76ce48fb718f
< 2.8.1
MEDIUM 6.4 The Linear plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.0 due… wordfence
ae92bd0c-936c-4fae-8c0c-c94706568527
< 3.6.1
MEDIUM 6.4 The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it… wordfence
ae920b3b-6c6f-46c5-b64f-c075a53b4c39
< 3.6.0
MEDIUM 6.4 The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Addi… wordfence
ae8f1852-2d67-4ed9-ab3d-5b3bf4083e06
< 1.0.1
MEDIUM 6.4 The URL Media Uploader plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and incl… wordfence
ae8c888e-46ed-468f-a5d5-74a7f9d01a36
< 11.0.12
MEDIUM 6.4 The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the media URL in versions up to, an… wordfence
ae7fa018-c87f-463b-84a3-bbe71b73d3dd
< 1.30
MEDIUM 6.4 The VdoCipher plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.29 d… wordfence
ae7f76ef-3f97-4889-8902-f13a4a298475
< 3.1.4
MEDIUM 6.4 The Graphina - Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multipl… wordfence
ae768e43-9a77-4b00-bdac-f82c5dae5dd8
< 2.7.5
MEDIUM 6.4 The Widget Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
ae68ab4f-d3a5-4287-9fe6-f8b1dfa59e77 MEDIUM 6.4 The Selar.co Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
ae42395f-703c-4cdb-9aa5-35ce9dfaeb16 MEDIUM 6.4 The Video Playlist For YouTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
ae3dd251-3415-4a7f-93d9-c0fe23b5ed31
< 4.14.2
MEDIUM 6.4 The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4… wordfence
ae3974e6-cba1-4976-a6af-9e60557cfde8
< 1.2.6
MEDIUM 6.4 The Parallax Slider Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
ae0a001b-0792-4a32-8f49-5d4b1550f4be
< 2.20.0
MEDIUM 6.4 The Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Ba… wordfence
ae08900f-9e08-4297-a450-7174d0e3579a MEDIUM 6.4 The Podcast Feed Player Widget and Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
ae04e9f2-0260-44bd-9439-cabf9d00fc2c
< 3.1.1
MEDIUM 6.4 The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '… wordfence
ae048156-f6a0-41c3-8853-ea439eac10a4
< 1.1.4
MEDIUM 6.4 The Power BI Embedded for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_power_bi… wordfence
ae039144-2c02-4a00-9fff-f4e90a6a8236
< 4.10.0
MEDIUM 6.4 The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cr… wordfence
adfba556-6a96-4836-af0f-39c214099481
< 5.0.8
MEDIUM 6.4 The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'w… wordfence
adf6b34b-a362-4cfe-b062-8bbe11584581
< 1.6.5
MEDIUM 6.4 The Portfolio Gallery – Image Gallery Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
adf10ad4-38b2-44be-bdc6-ba6b62e9fbe6
< 0.4.4
MEDIUM 6.4 The Squelch Tabs and Accordions Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu… wordfence
adf10688-834c-4922-89a3-0048dde5f210
< 4.0.5
MEDIUM 6.4 The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… wordfence
adf03af6-f454-41c6-bb65-87c7f5d7c465 MEDIUM 6.4 The MK Google Directions plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
← Prev 566 567 568 569 570 571 572 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top