πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 578 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a6e687e9-6ffe-4457-8d57-3c03f657eb74 MEDIUM 6.4 The ImageMapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'imagemap' shortcode in versions u… wordfence
a6e3645d-ed1b-4c51-a463-c2691cb7168d
< 26.0
MEDIUM 6.4 The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to … wordfence
a6df96a3-d56b-4eac-af33-92f4a76e3902
< 1.2.16
MEDIUM 6.4 The Astra Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
a6da4cf6-4b3b-4015-9106-b2a4467f34f7 MEDIUM 6.4 Stored XSS in the Contact Form 7 Datepicker plugin through 2.6.0 for WordPress allows authenticated attackers with minim… wordfence
a6d663a9-3185-4c36-b9d1-878297965379
< 1.12.2
MEDIUM 6.4 The Giveaways and Contests by RafflePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'raf… wordfence
a6cee2c1-cdfb-419a-8900-bc9d921d610e MEDIUM 6.4 The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
a6be4aaa-f8a1-42d6-95c1-062c5ca51004
< 2.4.32
MEDIUM 6.4 The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnera… wordfence
a6be4565-d5e6-43f8-bdd2-e6dce66bdad2
< 2.5.1
MEDIUM 6.4 The EazyDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.0 d… wordfence
a6b5cca3-7911-4bb0-b54b-ae19ce570c5c
< 5.5.4
MEDIUM 6.4 The Logo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.… wordfence
a69e9802-9087-4cd9-86eb-b64a82bc7c0b
< 2.4.16
MEDIUM 6.4 The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a… wordfence
a69a99af-3d1d-4ad2-b6b5-e4fcea56be51
< 6.7
MEDIUM 6.4 The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusedesk_newcase' short… wordfence
a684f597-da72-4697-9e37-ca45a30ca64d MEDIUM 6.4 The Dominion – Domain Checker for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p… wordfence
a684bf5f-7cf6-43b1-b457-fdc2ba74852d
< 3.4.14
MEDIUM 6.4 The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'su… wordfence
a6811f19-07fb-4c05-977f-90f9c5d89bb4
< 5.25.25
MEDIUM 6.4 The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
a67df40b-7179-47a7-9cde-1c512ecc2253
< 1.2.1
MEDIUM 6.4 The Themify Portfolio Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes… wordfence
a67b4ec2-b337-478f-aaaa-2ce19c4deb4c MEDIUM 6.4 The List Attachments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_list' p… wordfence
a66bc196-e5f8-46b4-a81c-c888eb64021c
< 3.2.71
MEDIUM 6.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_log… wordfence
a66b55e0-1b31-4d5f-bcc1-cfd38b613905 MEDIUM 6.4 The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attri… wordfence
a666d0e4-4fa7-4794-b270-afbccf5036c6
< 3.5
MEDIUM 6.4 The BUKAZU Search widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode' parameter… wordfence
a660b7b8-550e-42d7-b15a-0ab2aa501623
< 7.1.2
MEDIUM 6.4 The Donorbox plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 7.1.1 via stor… wordfence
a65fe73b-6bcb-4856-a76c-fbcb6cf3c3bd MEDIUM 6.4 The WP Joomag plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.2 … wordfence
a659866a-65d0-42b3-be39-b600a065d5bf MEDIUM 6.4 The RRSSB plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.1 due … wordfence
a654ee62-8742-49bc-95fd-bfab14750b50 MEDIUM 6.4 The 360 Photo Spheres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sphere' shortc… wordfence
a64c67de-1c16-4dcb-a3e4-81341b37c3e3 MEDIUM 6.4 The Mega Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
a63d6a64-aaba-4744-a372-89e1c0ce00df
< 3.12.1
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
← Prev 575 576 577 578 579 580 581 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top