🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 570 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
adea27d5-093d-4c66-ab0f-69b4ab8dc261 MEDIUM 6.4 The ra_qrcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.0 … wordfence
ade7f391-3824-4d0b-8718-f7995170a43d
< 3.10.6
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in widget… wordfence
ade27af2-bc3d-45b1-a881-9e0e1182feee MEDIUM 6.4 The bbp topic count plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
ade1eddf-cfcc-4956-8015-8d9a592cc252
< 1.3.3
MEDIUM 6.4 The Gum Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Meta widget in al… wordfence
add85b9b-3a4d-4c46-a90f-10c9645e249d MEDIUM 6.4 The Smart App Banners plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' and 'verticalalig… wordfence
add39d28-4070-44e2-8dff-0371e0c58453
< 1.8.8
MEDIUM 6.4 The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor’ param… wordfence
adcab262-08ca-448d-b1fd-295d421b82a3
< 1.2.5
MEDIUM 6.4 The Solar Wizard Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'solar_wizard' … wordfence
adb54754-2994-47ad-99f8-e8d2d235da3d MEDIUM 6.4 The Hover Video Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
ad993a62-457a-494f-a7c8-256b808d18c0
< 10.14.7
MEDIUM 6.4 The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bookingcalendar' … wordfence
ad95f0b2-4d96-4f62-b495-050a89539177 MEDIUM 6.4 The SVG Uploads Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG files in all versions … wordfence
ad945b6f-7405-4ef7-acb2-5ee698b4a3ca MEDIUM 6.4 The Gallery – Photo Albums Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
ad9272e3-fa81-440e-8d77-207145123ad2
< 1.2
MEDIUM 6.4 The Easy Twitter Feed WordPress plugin before 1.2 does not sanitise or validate the parameters from its shortcode, allow… wordfence
ad8b5fd2-ba92-4afa-9b4a-a95936b9a18d
< 1.5.3
MEDIUM 6.4 The Kaya QR Code Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter pas… wordfence
ad862fff-4195-4aac-8fe4-8e7b9b49294a
< 2.2.6
MEDIUM 6.4 The Gallery Custom Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
ad6b8346-6bc1-4d6b-9d4f-9b25fbe3962f MEDIUM 6.4 The FAQs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0.2 d… wordfence
ad66d4ec-02ee-4b56-91ce-29f336df9410
< 1.1.31
MEDIUM 6.4 The LightBox Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
ad62fd9b-fbd5-4e3d-b910-29143c6813b7 MEDIUM 6.4 The DD Rating plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1 … wordfence
ad48182f-9ad0-49d9-a3c5-805830dca530
< 5.0
MEDIUM 6.4 The Add Custom Codes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
ad39a3b0-5434-4595-a052-4b6e4adb2247
< 1.3
MEDIUM 6.4 The Display During Conditional Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘me… wordfence
ad0ed141-3d17-4fff-b788-7ff43f79d04c
< 2.8.4
MEDIUM 6.4 The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
ad0e684a-6bae-44cb-a43c-6bc402217f20
< 3.5
MEDIUM 6.4 The Popup addon for Ninja Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
ad0e4292-d890-499b-b70a-ed638d5b8ee9
< 3.2.37
MEDIUM 6.4 The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'li… wordfence
ad01d01a-d1d9-4c4e-9818-52298c2df89c
< 2.0.8
MEDIUM 6.4 The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
acff618e-1fed-49c6-8713-c58d32b73382 MEDIUM 6.4 The Video Embed Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
acf69e07-884c-4eaf-8b58-c1fd3810e086 MEDIUM 6.4 The dbview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dbview' shortcode in all … wordfence
← Prev 567 568 569 570 571 572 573 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top