🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 581 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a44cde91-2f4d-40f1-98a1-ee6ed94c0155
< 4.0.5
MEDIUM 6.4 The MainWP Google Analytics Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and … wordfence
a443b20e-1686-4519-890d-e6f1838fb05c
< 4.3.0
MEDIUM 6.4 The Mega Addons For WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
a43adbf2-0e85-4e70-a18f-8001a86b224e
< 3.3.5
MEDIUM 6.4 The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting atta… wordfence
a42dce68-0e64-46a6-926e-b676071744b9
< 2.5.17
MEDIUM 6.4 The My Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘event_time_label’ paramet… wordfence
a427c798-f546-4ca1-98ab-32b433ee5b59
< 3.9.15
MEDIUM 6.4 The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gu… wordfence
a4246181-d331-46b0-ad48-e2ece11b2f5f
< 3.11.5
MEDIUM 6.4 The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post custom field keys (meta key … wordfence
a412e682-869a-46ba-a2d0-d84ed542adc9
< 5.5.0
MEDIUM 6.4 The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ele… wordfence
a3fbf26b-c7d8-4c44-b3c1-c4e028465a9e
< 1.6.8
MEDIUM 6.4 The Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfoli… wordfence
a3f22e95-4b2f-47d5-bb99-0c6497fed893
< 1.1.29
MEDIUM 6.4 The Contact Form Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form fields in all version… wordfence
a3e61538-0bd9-4319-ba71-a72c9039f4d8
< 2.4.8
MEDIUM 6.4 The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_… wordfence
a3d14467-0c1d-4741-b533-37b9605c5fde MEDIUM 6.4 The Sales Page Addon – Elementor & Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
a3c323d5-59bc-4ecc-8211-2104fd22639f MEDIUM 6.4 The iframe Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in … wordfence
a3bb454c-ac0e-4915-8c6e-070596f7595a
< 4.9.0
MEDIUM 6.4 The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an… wordfence
a3b89d04-8a67-4744-a590-3b4dec830906 MEDIUM 6.4 The Custom Content Scrollbar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
a3b5c7ec-eb6a-492e-962f-6ed47ee7f1f2
< 3.1.20
MEDIUM 6.4 The Nextend Facebook Connect plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
a3b164e0-de2e-40d5-935e-31f5bebd87cf
< 2.0.8
MEDIUM 6.4 The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in v… wordfence
a3ad7383-613b-4286-b1d3-ee12dc80fbe2
< 1.0.20
MEDIUM 6.4 The Featured Video for WordPress – VideographyWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
a3a3d97d-c01a-485b-80cd-f3195599e159
< 1.9.3.2
MEDIUM 6.4 The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
a3a37e6a-659b-4a40-9051-9e8b3ca1ad42
< 1.2.6
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authe… wordfence
a3845b4f-47c2-4b0b-af14-2d63bd74459c
< 1.5.2
MEDIUM 6.4 The DSGVO Youtube plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
a3798336-e63b-4ede-9e4d-09a28249ea46
< 1.3
MEDIUM 6.4 The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
a36e599a-c8fb-42e2-acc0-d76a77dce336 MEDIUM 6.4 The SEPA Girocode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.… wordfence
a3659c4d-3a19-4f74-9f6d-26d7b24ebe56
< 4.4.3
MEDIUM 6.4 The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions … wordfence
a362e60d-e4ab-4f19-9e18-5473d8e13d80
< 2.0.5.6
MEDIUM 6.4 The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
a35b5dbd-6d29-404f-9363-a5787d35169c MEDIUM 6.4 The Pastebin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5 due… wordfence
← Prev 578 579 580 581 582 583 584 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top