🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 585 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a0a5ebb4-319b-421e-bf69-a9403ca96e85 MEDIUM 6.4 The Supermalink plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1 … wordfence
a09113d3-8be0-45fa-b1d7-4eb6ebb1780e
< 1.1.1
MEDIUM 6.4 The AVIF & SVG Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versio… wordfence
a04f074c-448d-4c5f-ae46-0ad1a3effdb4
< 4.8
MEDIUM 6.4 The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's … wordfence
a0489172-279c-4397-a937-bca4840a196f
< 8.5
MEDIUM 6.4 The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… wordfence
a03e825f-bccf-4e1a-b3f5-86b0c6958b79
< 2.9.5.3
MEDIUM 6.4 The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.5… wordfence
a035f385-5e96-4d6c-8bcf-7db282b40e2d MEDIUM 6.4 The newseqo theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 due… wordfence
a0336e35-eb3c-4613-b8a2-fac7b837eb6f
< 3.7.5
MEDIUM 6.4 The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the insert shortcode offered by t… wordfence
a02f0a23-0b2b-4e16-9f6d-ec6302a0d23b
< 1.0.17
MEDIUM 6.4 The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget button URL… wordfence
a022860a-07d1-44f8-8c5b-965c855822fd MEDIUM 6.4 The Able Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 … wordfence
a0214cf8-59f7-4928-bf27-547f3b7790ae
< 1.3.0
MEDIUM 6.4 The Excellent theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.2… wordfence
a013106b-4e2a-4dd9-a0ab-7e6c91e715dd
< 1.6.2
MEDIUM 6.4 The Structured Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Classic Editor… wordfence
a0101dd1-a9cb-4b9c-8299-9b808d7e1912
< 1.0.7
MEDIUM 6.4 The Attributes for Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributesForBloc… wordfence
a00a5c41-b211-45e4-acf8-01fd8e64b1c0
< 1.6.38
MEDIUM 6.4 The One Page Express Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's one_pa… wordfence
9ffdc255-1b39-4e08-b75a-a155f8156fb4 MEDIUM 6.4 The Sliding Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
9feb44e1-eb19-40eb-85d6-fae56afe90ee MEDIUM 6.4 The Meet My Team plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0… wordfence
9fe9fe85-bcb5-4e12-b879-31bc73074eed
< 3.5.2.1
MEDIUM 6.4 The JetSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versio… wordfence
9fe3d648-d6b3-4363-b449-bfc0f5b9c1ea
< 3.13.3
MEDIUM 6.4 The Fusion Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3… wordfence
9fe1178e-aca3-4f52-85e1-7d04b866a073
< 3.0.2
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers … wordfence
9fd58c6b-2ed5-4f6c-bb49-bc0151f72f73
< 3.1
MEDIUM 6.4 The Awesome Contact Form7 for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
9fd517d9-4966-4cb6-86c2-4881de3d1d53 MEDIUM 6.4 The Get Cash plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.2 d… wordfence
9fd3610c-cce4-420c-85c1-0b71679df650
< 2.4.0
MEDIUM 6.4 The Sellsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testSellsy' shortcode in … wordfence
9fcf8baf-502f-4e72-b217-e80f7ca136df MEDIUM 6.4 The NewsDaily theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.64 … wordfence
9fcf7936-8a28-45b9-a9dc-fd7257a83a84
< 1.4
MEDIUM 6.4 The Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in a… wordfence
9fcd21a6-ca6b-491c-8736-cf6d81883378
< 0.6.40
MEDIUM 6.4 The YaMaps for WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to,… wordfence
9fc6d947-4b6e-4dcb-9f20-02e39b4e730e
< 2.2.7
MEDIUM 6.4 The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which c… wordfence
← Prev 582 583 584 585 586 587 588 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top