πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 576 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a8c547cc-2820-4138-b042-a0ec2e7f2fca
< 2.6.9.9
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Ca… wordfence
a8b7621a-54bf-4c38-824c-4aff49a988f9
< 1.5
MEDIUM 6.4 The List Mixcloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
a8b6dafb-7b2f-4459-95bd-eb7e147a4466
< 1.58.3
MEDIUM 6.4 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the features attribu… wordfence
a8b1feee-431f-4406-b7c0-a7e71cb5f179
< 9.99.2.0
MEDIUM 6.4 The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
a8ada876-4a8b-494f-9132-d88a71b42c44
< 2.7
MEDIUM 6.4 The Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcpaccordion' shortcod… wordfence
a8a5b5ce-9975-449b-bdd1-d139f1360297 MEDIUM 6.4 The Shortcode for Google Street View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'streetvi… wordfence
a8971d54-b54e-4e62-9db2-fa87d2564599
< 3.2
MEDIUM 6.4 This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to,… wordfence
a87d0966-3fd4-46f8-acd5-1cf0cb18af42
< 3.3.6
MEDIUM 6.4 wordfence
a85f7ddb-b784-45d4-9d2f-a636c12e7f85
< 1.2.9
MEDIUM 6.4 The WP Education plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2… wordfence
a85caa9f-1c69-41ea-a237-dcb6b4f297bb
< 3.19.6
MEDIUM 6.4 The Stackable plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.19.5… wordfence
a85461b7-6d16-435c-a149-ad25419a1585
< 3.8.2
MEDIUM 6.4 The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
a84bd9c8-97bd-4572-8bfa-5191d98c9523
< 2.1.0
MEDIUM 6.4 The Constant Contact Forms by MailMunch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown… wordfence
a847aea8-5e15-4c0e-bc16-27198e83c171
< 1.4.20
MEDIUM 6.4 The Xpro Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
a82fd49e-6e95-4743-900a-fa53b870ec0b
< 1.3.0
MEDIUM 6.4 The SVGator – Add Animated SVG Easily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File u… wordfence
a82debfe-e346-491f-a6dc-1bbf1a363999
< 7.2.1
MEDIUM 6.4 The Shortcodes Ultimate Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_plan'… wordfence
a826dff8-60ae-4e25-9d3e-be93f192aaca MEDIUM 6.4 The Standout Color Boxes and Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's … wordfence
a818abe9-5520-4c63-9b41-52865ebd1820
< 1.10.3
MEDIUM 6.4 The Flexible PDF Coupons – Gift Cards & Vouchers for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
a80c306e-323b-4ab4-955b-4e264625731c
< 4.5.1
MEDIUM 6.4 The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in ver… wordfence
a807658d-cdfc-48cc-8dfe-1dd2773fcbcf MEDIUM 6.4 The CoziPress theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.32 … wordfence
a8059995-55cb-49ee-add1-f5364d0772eb
< 3.0.19
MEDIUM 6.4 The Contact List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_cl_map_iframe' parameter in… wordfence
a7f2a3b2-868a-4297-a609-73cb189e8cfc MEDIUM 6.4 The My Resume Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
a7f1a21c-2de0-4f41-b61e-7c4742900762 MEDIUM 6.4 The Translate This gTranslate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜bas… wordfence
a7eeb557-0528-422a-aae7-3f99154953df
< 3.2.13
MEDIUM 6.4 The Popup Box – Easily Create WordPress Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
a7e27a6c-8b14-459b-aba2-044f311edf9e
< 2.1.1
MEDIUM 6.4 The Posts and Products Views for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p… wordfence
a7d340b9-6a77-481c-983c-f4774ecff285
< 1.0.2
MEDIUM 6.4 The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, … wordfence
← Prev 573 574 575 576 577 578 579 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top