ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 583 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a25fbc55-12b8-4074-a5be-195b8ecc01fd
< 1.6.0
MEDIUM 6.4 The Pro Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
a25e5882-829e-4759-9c71-1d69ce4cf317
< 2.0.18
MEDIUM 6.4 The jAlbum Bridge plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
a25ad405-a97e-4821-b57a-0f39d5ce5e70 MEDIUM 6.4 The Simple Alert Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Alert shortcod… wordfence
a2520d98-3cee-4431-bf9c-b2fd01a584ce
< 3.2.8
MEDIUM 6.4 The Ultimate Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in… wordfence
a24c2d7d-8df8-4a3a-a538-09e11ebc6dd5
< 2.0.0
MEDIUM 6.4 The Blog, Posts and Category Filter for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
a2495fd6-5a36-4bdf-b4e0-68095072d820 MEDIUM 6.4 The Slick Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slick-sitemap' sho… wordfence
a2452dd7-2bb9-4a0c-81db-6699a9b049ae
< 5.3.6
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text parameter in a… wordfence
a22c7b45-752c-482d-8812-888d5bc3d630
< 1.3.0.1
MEDIUM 6.4 The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link in … wordfence
a223c8b4-6657-40f0-a040-9867595dbf64
< 4.7.0
MEDIUM 6.4 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Store… wordfence
a2110d13-d6d3-43f8-b1bf-8958d4f39ef5
< 1.1.3
MEDIUM 6.4 The Debrandify · Remove or Replace WordPress Branding plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
a20ef41d-7f01-4ef2-aae0-0b254ea78bc5 MEDIUM 6.4 The Consensus Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's consensus shortco… wordfence
a20288de-5f89-4ca3-ae6b-44ab6e1e18c3
< 1.1.1
MEDIUM 6.4 The Video Gallery Block – Display your videos as a gallery in a professional way plugin for WordPress is vulnerable to… wordfence
a1fa4293-2291-4273-93c4-404770a9c560 MEDIUM 6.4 The AdWords Conversion Tracking Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
a1da201f-47e3-4f39-9c8b-cd842e8f7ca5
< 2.3.3
MEDIUM 6.4 The themesflat-addons-for-elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
a1d72530-cfbb-4dfa-9acb-501f0c3a9651
< 2.2.1
MEDIUM 6.4 The Clever Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Scroll to widg… wordfence
a1d5c661-ebaf-4752-8263-ce6dc2f355cd
< 4.7.0
MEDIUM 6.4 The AI ChatBot for eCommerce – WoowBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
a1cec715-d19b-48b4-a924-5fb3f9a269ee
< 2.1.9
MEDIUM 6.4 The Enter Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1… wordfence
a1c2dc9d-99a2-4276-b968-50601afd85c3
< 8.92.0
MEDIUM 6.4 The Smart Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.… wordfence
a1b043a1-7bee-4ef0-86d9-19cf202cfc71
< 26.0.7
MEDIUM 6.4 Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all vers… wordfence
a1adaf1f-df0a-4793-805f-879f91acbd16
< 6.2
MEDIUM 6.4 The Penci Shortcodes & Performance plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
a1a2b205-9330-4296-9411-58f2f91e1f5e
< 0.6.41
MEDIUM 6.4 The YaMaps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
a19e1713-1a64-46dc-8b30-b53045b2e01d MEDIUM 6.4 The Mapplic Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions … wordfence
a19e11e7-faa1-4e4d-87de-2454c4ad70f8
< 1.1.7
MEDIUM 6.4 The CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout plugin for WordPress is vulnerable to… wordfence
a19bdf2c-d348-4c3e-9dc4-dfd54f77c973
< 3.5
MEDIUM 6.4 The Audio Comparison Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
a188c615-513b-4d65-8351-d70848696297
< 3.0
MEDIUM 6.4 The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rescue_progress… wordfence
← Prev 580 581 582 583 584 585 586 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top