πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 584 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a187fa8b-daf1-4955-92b3-2937d0f6a159 MEDIUM 6.4 The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' parameter in t… wordfence
a175e103-ab89-404b-8736-94d0d93d6cf3
< 1.0.36
MEDIUM 6.4 The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Op… wordfence
a16c8b5d-fd93-49b4-b1d7-f4cd9248aef3
< 1.2.5
MEDIUM 6.4 The Maps for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MapOnePoint' shortco… wordfence
a1640612-1516-42d7-9fdc-ed4eaa2f0eeb
< 1.2.3
MEDIUM 6.4 The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
a1629e77-0a98-4cb1-a36d-d9ff3f4bfaf1
< 2.1.7
MEDIUM 6.4 The Easy Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
a1603dc9-7f5e-47e1-8a81-27bb4df1aa4f
< 3.12
MEDIUM 6.4 The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
a15f8a5a-dccf-476e-9a40-e9ea11dc46f6
< 3.3.8
MEDIUM 6.4 The MyBookTable Bookstore plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SEO post data in version… wordfence
a153d6b2-e3fd-42db-90ba-d899a07d60c1 MEDIUM 6.4 The Simple Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to… wordfence
a1525119-732d-4948-9c33-75e9f3517c0d
< 29.0.0
MEDIUM 6.4 The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Sto… wordfence
a1510984-571b-49ce-9e10-129e2a1aca7b MEDIUM 6.4 The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_aj… wordfence
a14fe294-e6e3-42ca-9388-ea632bbc0ec7
< 2.7.4.5
MEDIUM 6.4 The Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
a1192c12-a898-46d9-9eee-6f611e644676
< 1.4.25
MEDIUM 6.4 The Xpro Addons β€” 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
a116c846-72df-4701-893a-744a26b191d6
< 1.5.23
MEDIUM 6.4 The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
a110bc69-ecf6-424d-9e2b-898a452d2dd1 MEDIUM 6.4 The Transition Slider – Responsive Image Slider and Gallery plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
a10ee67a-7f5f-43dd-8f5c-c0e92706c453
< 1.6.16
MEDIUM 6.4 The LocateAndFilter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio… wordfence
a10cf70e-bc66-4888-b88d-c1c4847389c9
< 2.2.27
MEDIUM 6.4 The DearFlip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'force_fit ' parameter in version… wordfence
a10965ef-472f-4e8b-a061-58854ce46f05
< 1.3.5
MEDIUM 6.4 The Mini Ajax Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
a0f47bf8-8dba-4b0b-94e5-fa4aaa61d6c9 MEDIUM 6.4 The Location Click Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
a0e28aca-b95f-4041-a1ea-4be84dc55923
< 7.4.38.727
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37… wordfence
a0de0b28-fbad-4fcf-a7ab-35c545c19a4a
< 6.5.4
MEDIUM 6.4 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Store… wordfence
a0bb1036-3e45-4ac9-b920-3b9629a3a724
< 6.4.5
MEDIUM 6.4 The MaxGalleria plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's maxgallery_thumb shor… wordfence
a0b9499b-3017-46a6-80d5-104d203b77f0 MEDIUM 6.4 The Mini Program API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'qvideo' shortco… wordfence
a0b5b6bc-5f4f-4cf8-987e-b20e8354d863
< 4.5.4
MEDIUM 6.4 The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress… wordfence
a0adfd13-a9f1-4bec-96ec-6a51cd08e4ea
< 2.0.5
MEDIUM 6.4 The Email Reminders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜id’ parameter in all … wordfence
a0ac8a41-553e-473b-82a7-226de17e472d
< 2.8.51
MEDIUM 6.4 The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜bbp_topic_title’ p… wordfence
← Prev 581 582 583 584 585 586 587 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top