ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 573 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ab650b99-ab15-4ddc-a622-cb43ab554ba7
< 1.34.1
MEDIUM 6.4 The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
ab63f507-6288-48e2-81c8-52b8a8c0c28c MEDIUM 6.4 The Spin 360 deg and 3D Model Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
ab5f43c0-83d3-4d09-becd-a3552bebd609
< 1.13.6
MEDIUM 6.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ paramet… wordfence
ab5e09d8-6fa3-4a5b-bee1-6648df4f4b3b
< 3.3.3
MEDIUM 6.4 The Visual Portfolio, Photo Gallery & Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
ab5b7dc4-113d-4f58-956e-2a9284e1e25e
< 1.0.23
MEDIUM 6.4 The Email Address Encoder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's eae_shortco… wordfence
ab518a1b-304d-4b93-b807-65ef3941dd47 MEDIUM 6.4 The EG-Series plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [series] shortcode in a… wordfence
ab4e8423-9169-4ea3-b519-522e858e8374 MEDIUM 6.4 The Renden theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, an… wordfence
ab478a98-3f76-4712-9a0f-99bfe27043e1
< 6.19.5
MEDIUM 6.4 The SeedProd Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 6.19.5 due to insuf… wordfence
ab4149e1-8378-4007-bbf2-1ac3c479e7ea
< 2.5
MEDIUM 6.4 The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functiona… wordfence
ab3176b5-fa24-4e06-9c0f-f4b0db4998ef MEDIUM 6.4 The Semantic Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
ab29af00-587b-45ab-8be2-4a03d8039427
< 5.4.2
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
ab19f7b1-2b1e-43bc-9843-ddee0fc74f50
< 1.0.48
MEDIUM 6.4 The SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything! plugin for WordPress is vulnerable to … wordfence
ab15fe2b-974c-41b0-ab6b-68322d2d3396
< 5.5.0
MEDIUM 6.4 The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown wi… wordfence
aafb5402-3553-4c89-86e0-4dd556d86074
< 1.0.94
MEDIUM 6.4 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
aade146b-029e-40c8-852f-879b6b57ee90
< 2.1.15
MEDIUM 6.4 The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
aad6afb6-0098-4bdd-b002-9798547d27e4 MEDIUM 6.4 The Stockholm theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.14.1 … wordfence
aad6151a-6897-4d0c-9dfb-0f424c683111 MEDIUM 6.4 The Plugin README Parser plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘target’ paramete… wordfence
aace327b-7091-48e2-9e02-ec48a08b129b
< 5.7.2
MEDIUM 6.4 The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to St… wordfence
aac9569e-d33d-45b3-bd03-2e7f48536ae5
< 2.5.6
MEDIUM 6.4 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
aac2b2a3-5d4f-449f-876c-d1bec295e088 MEDIUM 6.4 The Integration with Hubspot Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hubspotfor… wordfence
aac15273-0a5d-4107-8249-7fff7f503005
< 2.3.0
MEDIUM 6.4 The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldTy… wordfence
aabf1911-5c6f-4486-a750-d5c95f5815ba MEDIUM 6.4 The Quick Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quick-login' … wordfence
aab54795-31e7-4ef4-8a80-7443abaa3f21
< 1.1.3
MEDIUM 6.4 The Passwordless Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
aab33299-f02d-44a1-9522-5309eed6fd38
< 3.30.0
MEDIUM 6.4 The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
aab18839-6edc-4f8f-8e1f-ae305a4ed6b3 MEDIUM 6.4 The WPoperation Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
← Prev 570 571 572 573 574 575 576 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top