πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 572 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ac004fb0-e178-4e9b-9aa3-b14eab43f22d
< 11.1.34
MEDIUM 6.4 The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
abfa93e3-c07c-409f-87ea-28397af46fac MEDIUM 6.4 The WP-SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions… wordfence
abf30bd9-68ad-4204-9b70-8a6766d49ad5 MEDIUM 6.4 The Showeblogin Social plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
abe8c6b0-b16b-4391-88b4-dca507c973fc
< 2.31.1
MEDIUM 6.4 The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label param… wordfence
abe8133e-1407-43b5-a1fc-be800bd2aaca MEDIUM 6.4 The Bookalet plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.3 d… wordfence
abe3cedb-53f3-48ff-a731-df6a83f0da1a
< 1.13.2
MEDIUM 6.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
abe2f596-b2c3-49d3-b646-0f4b64f15674 MEDIUM 6.4 The Contact form Form For All plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortco… wordfence
abdb6632-d579-4650-b058-da10201cca8c
< 1.6.2
MEDIUM 6.4 The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Ta… wordfence
abda182f-411c-4c77-a1eb-23475e725ba2
< 1.3.0
MEDIUM 6.4 The Exchange Rates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
abd92465-9f61-4170-9676-e90bbd962c0c MEDIUM 6.4 The audioCase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.1 … wordfence
abbdf198-b6f3-41dd-ada1-b14fc9946142
< 5.0
MEDIUM 6.4 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
abb7def7-df32-4901-b8ea-068ff1af664b
< 2.0.4
MEDIUM 6.4 The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the heading tag dr… wordfence
abb64c22-f16e-4b4e-ac4f-86fde8a51bc6
< 4.1
MEDIUM 6.4 The Penci Recipe plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0… wordfence
aba673c8-694f-4ae7-96cb-3624e3cc0ed2 MEDIUM 6.4 The μ•„μž„ν¬νŠΈ κ²°μ œλ²„νŠΌ 생성 ν”ŒλŸ¬κ·ΈμΈ plugin for WordPress is vulnerable to Stored Cross-Site Scripting in v… wordfence
aba393f5-c8e4-485f-b488-70b26ffb5698
< 2.7.12.1
MEDIUM 6.4 The JetElements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
ab97f125-3a4a-4293-b218-07586c1c021c
< 1.3.2
MEDIUM 6.4 The Interactions – Create Interactive Experiences in the Block Editor plugin for WordPress is vulnerable to Stored Cro… wordfence
ab8ed134-651e-458a-9151-ee41634d01ea
< 4.10.5
MEDIUM 6.4 The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
ab8dfdd8-820c-4066-8014-2cb5b9f935a4
< 5.11.3
MEDIUM 6.4 The Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Bu… wordfence
ab8ce4cf-9085-49d2-a889-9d53272032c1
< 2.4.2
MEDIUM 6.4 The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a times… wordfence
ab888ee1-bdc2-4b8b-9b16-a7d146f123df
< 3.2.5
MEDIUM 6.4 The Easy Social Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in… wordfence
ab856722-e954-49de-a93f-46664da6e3e8
< 2.3.3
MEDIUM 6.4 The Live updates from Excel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ipushpul… wordfence
ab777672-6eef-4078-932d-24bb784107fa
< 2.2.65
MEDIUM 6.4 The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the c… wordfence
ab747c34-219d-40c8-a73d-5b0dffba003b MEDIUM 6.4 The Angel – Fashion Model Agency WordPress CMS Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
ab66ac69-0617-4f9f-8ad3-4ab1502892bd
< 3.5.1
MEDIUM 6.4 Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary… wordfence
ab664bc5-ef3c-4e5a-99d5-e3f1bb240a70
< 3.0.0
MEDIUM 6.4 The MarqueeAddons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial Marquee… wordfence
← Prev 569 570 571 572 573 574 575 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top