🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 582 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a3494e39-b4dc-46c1-9e8f-2c04fa3df940 MEDIUM 6.4 The Vimeo Video Autoplay Automute plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho… wordfence
a341a264-0b1a-47a2-8c7e-9a6e10c5ad0a
< 1.2.33
MEDIUM 6.4 The Superio theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4 due t… wordfence
a33c4524-6584-43a1-a523-6ea26eadda3d
< 2.5.6
MEDIUM 6.4 The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
a33c0e7e-42d3-442e-886e-e0a71cdbf628
< 6.4.8
MEDIUM 6.4 The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
a33a7ba5-c6f8-4cf4-8011-8312e9c5da8f
< 8.9.2
MEDIUM 6.4 The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Stored Cro… wordfence
a3335613-1206-4555-8e48-748a336548d4
< 2.4.0
MEDIUM 6.4 The Animate It! for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘onanimationend’ parameter in ver… wordfence
a31cf5d0-1c37-46bf-bf0c-ca820a281bfc
< 3.16.2
MEDIUM 6.4 The WP Rentals theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.16.1… wordfence
a3187d3e-e1da-4af7-a1fa-9657389f9e22
< 2.1.0
MEDIUM 6.4 The FluentAuth – The Ultimate Authorization & Security Plugin for WordPress plugin for WordPress is vulnerable to Stor… wordfence
a301c969-3f62-4377-926a-d36e47e833f0 MEDIUM 6.4 The WPBakery Visual Composer WHMCS Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
a2fe3ef1-2bd0-482a-b873-b373caaa75a4 MEDIUM 6.4 The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Serv… wordfence
a2dab9d3-a890-4c66-a825-e30329e37a60
< 8.14.1
MEDIUM 6.4 The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.… wordfence
a2d96212-f485-48c5-b8d5-d1d25eb65236
< 1.4.2
MEDIUM 6.4 The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
a2bf5c47-11e6-462d-a671-3f5e94e9e7e5 MEDIUM 6.4 The GPXpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gpxpress' shortcode in … wordfence
a2b9d080-489d-40e4-bb6f-c4209e5f4fad
< 2.4.26
MEDIUM 6.4 The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
a2b8e295-4183-4f84-801f-da9ffa6efce2 MEDIUM 6.4 The Gallery Factory Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes i… wordfence
a2b8d0f9-3fe1-4588-b81f-13d7db47afea
< 4.4.3
MEDIUM 6.4 Several plugins for WordPress by wpcodefactory are vulnerable to Stored Cross-Site Scripting in various versions due to … wordfence
a2b173e8-5bdd-4048-8201-2d66ce2f2eca MEDIUM 6.4 The WPB Advanced FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in … wordfence
a2a697f5-4888-438e-89b5-9355b9b06194 MEDIUM 6.4 The YouTube SimpleGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
a2a0940a-8a53-49bc-820b-bfbbfc408121
< 1.1.1
MEDIUM 6.4 The Web Stories Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
a29ebdcb-3b03-4504-b553-6f7633c68f3f MEDIUM 6.4 The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
a292579c-9755-4bd4-996c-23d19ca1c197
< 2.2.7
MEDIUM 6.4 The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘twitter_username’ paramet… wordfence
a27dfc37-81cf-4e95-a331-02fc952e34af MEDIUM 6.4 The Sphere Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in the 's… wordfence
a27aa8f5-9662-4e31-abc1-c8e71bb791db
< 2.0.2
MEDIUM 6.4 The FlippingBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0… wordfence
a2791f48-895f-4099-87ec-41aaac2494a2 MEDIUM 6.4 The Font Awesome Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fawesome' shortcode … wordfence
a276d70d-3ad7-49e0-a25c-8089cdd581da
< 5.0.3
MEDIUM 6.4 The AddThis plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘at_async_loading’ AJAX action… wordfence
← Prev 579 580 581 582 583 584 585 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top