πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 571 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
acf2906b-1ee5-4272-bf6d-36a02023f658
< 4.12.4
MEDIUM 6.4 The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-c… wordfence
ace85b25-251b-4549-8f6e-1a1494cbabb6
< 11.9
MEDIUM 6.4 The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod… wordfence
accdcff0-f361-4632-b0b7-e55975adeebb
< 1.6.46
MEDIUM 6.4 The WooCommerce Brands plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '[product_bran… wordfence
accd4f34-4e10-4c83-96c3-c2a078ecd5cc
< 2.8.14
MEDIUM 6.4 The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (… wordfence
acaadf62-08ff-4d2b-b998-47079cce4cd6 MEDIUM 6.4 The Links shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
acaad554-4094-4b52-a695-cb1e775495a5
< 1.5.12
MEDIUM 6.4 The Picture Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
acaa3142-2bbc-43d3-8ecc-05e8edb931ec
< 1.2.5.2
MEDIUM 6.4 Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled ligh… wordfence
aca48ddf-4256-4a55-bff5-1718110147dd MEDIUM 6.4 The Subpage List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'subpages' shortcode… wordfence
ac909a4b-d949-42eb-871a-963bc6242c12
< 3.6.0
MEDIUM 6.4 The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Server-Side Re… wordfence
ac8a8698-0f8d-4204-8539-ce129d98b2b4
< 1.0.7
MEDIUM 6.4 The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin … wordfence
ac87819d-0ba3-4c30-ae35-e933f7e250a4
< 3.2.3
MEDIUM 6.4 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shor… wordfence
ac7f95c7-2159-4327-ba09-da7721f1312e
< 2.5.7
MEDIUM 6.4 wordfence
ac7aeb6a-4e41-4301-8e79-ffe1468c0940 MEDIUM 6.4 The Data Visualizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'visualize' short… wordfence
ac7263c6-1c87-4747-869d-1aaeffa00d54
< 2.5.1
MEDIUM 6.4 The Wired Impact Volunteer Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
ac5d941c-f16c-4ba0-9981-65c527302c46 MEDIUM 6.4 The GreenCon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.1 d… wordfence
ac422162-be05-4420-9877-d6d41b83e881
< 3.2.8
MEDIUM 6.4 The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
ac41a122-9a17-45a0-9ba7-2790a07ac466
< 5.1.2
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
ac2f6549-016f-494d-99a4-52a1527f1fd2
< 2.0.13
MEDIUM 6.4 The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
ac18b418-ac7d-4cc3-b377-43e5a23b39ed MEDIUM 6.4 The Winning Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
ac1493dc-a90a-4427-a631-af5da65e1d6c MEDIUM 6.4 The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `… wordfence
ac1037b7-f822-447a-a4b5-d02ed6b70176
< 1.1.24
MEDIUM 6.4 The CubeWP Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
ac0dfaac-cce6-45f7-ad5b-d7dcb66453bd
< 1.1.3
MEDIUM 6.4 The Cards for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the BootstrapCard lin… wordfence
ac038d9d-f894-4856-affa-8993cf9e0bd3
< 3.0.8
MEDIUM 6.4 The Upsell Order Bump Offer for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
ac00d82b-4095-4c0c-8b5c-ecff9fa67067
< 2.3.8
MEDIUM 6.4 The SQL Chart Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
ac005402-0bac-453e-918d-b8a44abeff06
< 1.7.6
MEDIUM 6.4 The List Pages Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in… wordfence
← Prev 568 569 570 571 572 573 574 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top