πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 579 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a63bf106-78cf-441b-a1b3-77ec1cf6c22b MEDIUM 6.4 The Autogen Headers Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'head_class' paramete… wordfence
a61bfa95-96bc-45b8-a7b3-d356a5423097
< 1.9.10
MEDIUM 6.4 The Include Mastodon Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
a60d8102-1f15-4e61-b715-81e2111651a4
< 1.216
MEDIUM 6.4 The Add Link to Facebook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜c_al2fb_meta_clien… wordfence
a5fb289e-bd38-42ea-86a4-7816b59bd0b2 MEDIUM 6.4 The RT Easy Builder – Advanced addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
a5f4ed55-4e6c-48a3-acea-909e5a9d1a06 MEDIUM 6.4 The Mystique theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.7 du… wordfence
a5f0cb99-99e1-4c10-9d06-0c10df5f2581
< 2.0.2
MEDIUM 6.4 The Designil PDPA Thailand plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
a5de7f19-ecf8-4eb5-b048-9050edb7a27a MEDIUM 6.4 The Custom Database Applications by Caspio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… wordfence
a5da021c-3835-4251-a3e5-3b5aaa11ea14 MEDIUM 6.4 The Simple Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tweet this text value in all … wordfence
a5c0ae44-18e5-4fd1-a1a8-b70fc15a8c26 MEDIUM 6.4 The You Shang WordPress plugin through 1.0.1 does not escape its qrcode links settings, which result into Stored Cross-S… wordfence
a5ba7b53-5af7-4250-a0ec-e26672300683 MEDIUM 6.4 The IntelliWidget Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
a5b247a7-50f4-4d35-b24a-2c788ba0b051
< 2.12.0
MEDIUM 6.4 The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerabl… wordfence
a5a9fb50-8ab1-43e3-b618-d92fa50b3e07
< 1.0.0.41
MEDIUM 6.4 The Gallery Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
a5a84999-bd1b-4b86-9fa1-09c20b50ce37
< 1.8
MEDIUM 6.4 The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
a5a2a74a-6c6b-4a3c-94b8-894c689dbb60 MEDIUM 6.4 The Restaurant WordPress Theme | Ratatouille theme for WordPress is vulnerable to Server-Side Request Forgery in all ver… wordfence
a5a03e67-f36f-441a-a2fd-a545efa06c00
< 3.2.22
MEDIUM 6.4 The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputti… wordfence
a58cba26-a57e-4170-95bb-54ea7cfdb10c
< 0.89.7
MEDIUM 6.4 The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' sho… wordfence
a58bdc25-6171-47d5-bdcc-b4fe89b906f1
< 3.4.4
MEDIUM 6.4 The Ghost Kit – Page Builder Blocks, Motion Effects & Extensions plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
a576f39e-42de-4881-a490-000850ea1d2d MEDIUM 6.4 The Crowdfunding for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜width’ p… wordfence
a5719af3-b2d0-42c4-a509-8f4fbcd8eb2d
< 2.0.32
MEDIUM 6.4 The Simple SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2… wordfence
a54c2a89-4297-48f5-bbff-e5c20c26a632
< 5.3.3
MEDIUM 6.4 The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Regi… wordfence
a52e43dd-46b4-445b-b350-a2fd76315869
< 2.12
MEDIUM 6.4 The Spotify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
a4fdfc83-cce9-4c87-88f2-331be081b32c
< 5.6.3
MEDIUM 6.4 The The Plus Addons for Elementor Page Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
a4fa8aa9-0af8-4202-b219-863bbef8d02c
< 1.9
MEDIUM 6.4 The Restaurant Reservations plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
a4f6df09-a677-44bc-a2bb-88a7f14c7426
< 1.5
MEDIUM 6.4 The Create with Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
a4f6ce4d-6ca5-4a62-ae84-9dd190fc0392 MEDIUM 6.4 The Amazing service box Addons For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable t… wordfence
← Prev 576 577 578 579 580 581 582 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top