🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 580 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a4eeaf05-ec86-4d99-bc00-81f7f99e88ce
< 5.2.8
MEDIUM 6.4 The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a post's Featur… wordfence
a4e982d1-7ad9-490e-b606-695cafbc7f0b MEDIUM 6.4 The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings befor… wordfence
a4d16ccd-149a-4f70-84b4-59429827baa5
< 2.9.29
MEDIUM 6.4 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… wordfence
a4ccc7f8-c8e0-457a-b437-2a23530a9df4
< 2.4.1
MEDIUM 6.4 The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is … wordfence
a4cad5b2-eb0f-41f8-b43b-fcb70d185c25 MEDIUM 6.4 The Fitness Park theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.… wordfence
a4c7c932-5955-4fce-a64d-3b5c5de95356
< 1.3.14
MEDIUM 6.4 The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclu… wordfence
a4c480be-0987-4ce2-ac6c-c08d02786398
< 6.1
MEDIUM 6.4 The Penci Shortcodes & Performance plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 6… wordfence
a4b89902-5616-443f-b67d-bf3330308ef9 MEDIUM 6.4 Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark d.… wordfence
a4b44d89-6f1e-4a23-91ea-e79fc3221183
< 3.1.7
MEDIUM 6.4 The ColorMag theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions … wordfence
a4b353bf-f9be-465a-8723-9ea721b5baab
< 1.7.1
MEDIUM 6.4 The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
a4a0bf16-1a13-4955-8198-fa195fb65905
< 1.0.48
MEDIUM 6.4 The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing … wordfence
a49f8150-a27d-4801-8923-31af335c3cbd
< 2.17.11
MEDIUM 6.4 The Phlox theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption` HTML attribute in all … wordfence
a49eaeb9-1395-4ec3-b030-1de898ad0769
< 2.0.6
MEDIUM 6.4 The B Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.5 d… wordfence
a49e4f5a-ac9d-4f9b-8de2-c7871da8de35
< 2.7.4.3
MEDIUM 6.4 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
a49ba7e1-ef85-43d6-8685-4cb4e6b7208e
< 2.1.0
MEDIUM 6.4 The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
a49773ea-981a-4667-a56f-577db0fbf9c7 MEDIUM 6.4 The WP-Revive Adserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
a496d065-5821-4128-9363-79f388fdd246
< 3.0.7
MEDIUM 6.4 The Database for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
a47df134-21e1-4e36-b1b7-ea3e3115f0b6
< 1.4.8
MEDIUM 6.4 The Attesa Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4… wordfence
a47d79c1-ff14-4185-a088-25a65990a993 MEDIUM 6.4 The Power BI Embedded for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
a47c5496-2647-47f0-a772-b4e406a51c09
< 2.0.0
MEDIUM 6.4 The Pretty Google Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
a4601d9e-02bb-4b27-b16e-7cfc0fc19919
< 1.6.6
MEDIUM 6.4 The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accor… wordfence
a459bc57-0442-42bc-b60c-6eaf43aac7a6 MEDIUM 6.4 The Glossy Blog theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.3… wordfence
a4541890-4c0d-4348-91df-42cf4b575514
< 2.15.6
MEDIUM 6.4 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
a45417ce-d5dd-4706-adbb-d44670de6eb7
< 1.4.1
MEDIUM 6.4 The OpenSheetMusicDisplay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ para… wordfence
a452cb6f-8381-4f23-b808-3473db159894
< 0.7.5
MEDIUM 6.4 The EmbedStories plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in ver… wordfence
← Prev 577 578 579 580 581 582 583 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top