πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 574 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
aaa938a6-812b-4693-8f59-0f54b35023a3
< 1.3.0
MEDIUM 6.4 The Donate Me plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.5 … wordfence
aa8a095b-abda-4a12-a4b9-246cda41fb4e
< 3.7.24
MEDIUM 6.4 wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML elem… wordfence
aa85abba-e13f-42cd-8f13-432ed375fb37 MEDIUM 6.4 The Collapse-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
aa75a836-cbbd-4f56-a4f3-a1be4e4baa65 MEDIUM 6.4 The Bigmart Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
aa70238b-530e-4c90-82f4-c3113887d0e1
< 5.9.24
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
aa690c4d-15c4-43bc-b8f7-017b7741c5cd MEDIUM 6.4 The Easy Prism Syntax Highlighter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'co… wordfence
aa5f7f2a-c7b7-4339-a608-51fd684c18bf
< 1.6.1
MEDIUM 6.4 The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode… wordfence
aa5c2d05-f6cb-4f97-b174-653ad3577b02
< 3.0.0
MEDIUM 6.4 The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sr_se… wordfence
aa5bdaf9-fbde-40d4-a72a-fd24489818b3
< 5.9.15
MEDIUM 6.4 The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribu… wordfence
aa5505b7-2d9e-4a03-9655-75d004f53259
< 1.1.12
MEDIUM 6.4 The CBX Map for Google Map & OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu… wordfence
aa5075a8-1da1-4738-ad4b-b6c323d772ee
< 5.4.0
MEDIUM 6.4 The RD Station plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5… wordfence
aa441e45-9c33-483e-8332-49ac4dc7eaa3
< 2.1.4.8
MEDIUM 6.4 The WP Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions … wordfence
aa32a790-242f-4142-9f4d-e1b2a07045bb MEDIUM 6.4 The Live Chat with Facebook Messenger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
aa26e595-947c-4327-bbe1-c347688f1209 MEDIUM 6.4 The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a mis… wordfence
aa2507db-5efc-4468-803a-34c9c400f841 MEDIUM 6.4 The WP Chrono plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.4 … wordfence
a9ff662b-35e8-4a9d-8d74-3304ab976280 MEDIUM 6.4 The Show Visitor IP Address plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
a9f8ab73-8c2a-4551-bad9-4e5cc67231e5
< 2.0.3
MEDIUM 6.4 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to multiple Stored Cross-Site Sc… wordfence
a9ed2943-e108-49e3-ba16-f74ce3136bde
< 1.3.0
MEDIUM 6.4 The PrivateContent Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' shortcode attr… wordfence
a9e4b14f-0f55-47bc-8e40-19b262e50561
< 3.6.1
MEDIUM 6.4 The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Creative Button w… wordfence
a9dc828d-3b18-48fe-a0db-af26d3c1fa97
< 1.4.0
MEDIUM 6.4 The List Child Pages Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
a9d61a72-cced-457d-b6ca-d5b9f9936c5a MEDIUM 6.4 The DobsonDev Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embedPDF' s… wordfence
a9d32b7d-4218-4db3-93e2-246573b47dfc MEDIUM 6.4 The Multifox Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
a9ca2479-10ce-42ec-a9f3-0f91119d9525
< 2.2.2
MEDIUM 6.4 The Frontend Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
a9c6c35f-1095-4897-b4a6-e7b295c187de
< 1.5.8
MEDIUM 6.4 The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
a9a9bec8-7a76-4819-91c7-d9fdae3d94de MEDIUM 6.4 The BNS Featured Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bnsfc' sho… wordfence
← Prev 571 572 573 574 575 576 577 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top