πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 575 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a9a52097-0d85-4036-9b74-f35fea549607
< 4.0.2
MEDIUM 6.4 The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `the-subtitle` short… wordfence
a9a48769-94d9-459f-b34b-fdfe4c10b36c
< 2.0.6.0
MEDIUM 6.4 The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is … wordfence
a99b8eb9-1511-4ec0-98f4-c0e0c989fa28
< 6.7.11
MEDIUM 6.4 The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Add Layer widge… wordfence
a992dd59-ac56-4da0-9be7-fe32df440e5b
< 1.6.0
MEDIUM 6.4 The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's short… wordfence
a98498b8-9397-42e9-9c99-a576975c9ac9
< 3.3.16
MEDIUM 6.4 The Related Products for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'woo-related'… wordfence
a97f72f6-86f7-45dc-908a-292ba735071d
< 2.29.16
MEDIUM 6.4 The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteo… wordfence
a9747cda-735c-4087-8c4d-9c445c6d1596
< 2.1.5.1
MEDIUM 6.4 The WP Popups – WordPress Popup builder for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sp… wordfence
a96ac71f-3dae-40eb-9268-d56688a5aa64
< 4.0.1
MEDIUM 6.4 The GEO my WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to,… wordfence
a95d7ff6-55ce-4d63-8433-60cece306628 MEDIUM 6.4 The Anywhere Flash Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
a9521ae8-e20e-49dd-a402-5521f8d2d98e MEDIUM 6.4 The Paypal Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'amount' and 'name' short… wordfence
a9498085-87c7-47e7-aac8-c0397264a7eb
< 3.7.15
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in Word… wordfence
a939be31-7475-4626-ba1b-af9a9d6d5eda
< 1.3.5
MEDIUM 6.4 The Cliptakes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cliptakes_input_email'… wordfence
a92d53ab-9c59-4c9c-93e5-32dd05246249
< 1.3.10
MEDIUM 6.4 The Vayu Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
a91e8713-a760-4acd-9987-2a6b11dbdd56
< 6.3.3
MEDIUM 6.4 The WordPress Popular Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode… wordfence
a9162c2e-e765-4bda-b09f-982603b5797a
< 2.1.2
MEDIUM 6.4 Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow r… wordfence
a913ca7e-8f61-4615-b7fb-863b111fe22e
< 1.17.8
MEDIUM 6.4 The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter. wordfence
a8eab201-04a5-43df-bb9b-2964c50a1833
< 2.24.0
MEDIUM 6.4 The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
a8e39f0b-eb4c-4568-9f5a-60a0dc3eb6ba
< 1.7.1002
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
a8e222d1-cb03-4498-9776-e050eb501e9f
< 5.2.5
MEDIUM 6.4 The Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsc_displa… wordfence
a8de8a0b-0b70-4e8a-8cc4-06cc50d06a02
< 6.1.13
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for … wordfence
a8d9f6ba-1c41-4933-8eb2-8f27b9e87574
< 1.6.1
MEDIUM 6.4 The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Adv… wordfence
a8d5628e-b5d6-4f2f-b270-0fed1c7b34fa MEDIUM 6.4 The MX Time Zone Clocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
a8cce50c-2409-431d-80f4-13b8266a33a5 MEDIUM 6.4 The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
a8ca1ead-1bc5-4ccc-9034-559db27f5e82
< 3.9.28
MEDIUM 6.4 wordfence
a8c676a0-287f-479c-aaa1-ba638b340e11
< 1.3.3
MEDIUM 6.4 The Mega Elements – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu… wordfence
← Prev 572 573 574 575 576 577 578 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top