🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 592 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
994a5862-8855-42d4-94f9-0f65f552441d
< 6.0.1
MEDIUM 6.4 The Gianism plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.0.0 du… wordfence
992a5062-48f9-4028-9b4b-88cd6bf1bfd5 MEDIUM 6.4 The Qubely plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.14 du… wordfence
992474da-39c8-4299-bc6b-f1a967304afb MEDIUM 6.4 The DesignThemes Portfolio Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
99235898-127a-4f44-99e2-d60d37d3b85a
< 3.4
MEDIUM 6.4 The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
991aefb4-2e6b-48e6-bd19-98b21a57f6db
< 1.8.5
MEDIUM 6.4 The Quebely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in versi… wordfence
9915bd52-d77f-4c3f-92ef-8526d547e2f7
< 2.2.3
MEDIUM 6.4 The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
98fe007e-5a14-4a8b-9aa7-6ce836a3411e
< 2.0.0
MEDIUM 6.4 The jQuery TwentyTwenty plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
98f8a524-b0b8-4e11-b789-bed3bd257a10
< 5.2.2
MEDIUM 6.4 The Widget Options - Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'do_sid… wordfence
98f80608-f24f-4019-a757-de71cba9902f
< 4.0.0
MEDIUM 6.4 The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortc… wordfence
98f33f02-a46e-4578-a46b-0f355329aff8
< 3.2.54
MEDIUM 6.4 The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-… wordfence
98e883a5-4178-4f24-ba28-73760038d277
< 1.4.7
MEDIUM 6.4 The WP Notification Bell plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
98e74a23-b586-4d6a-b1ab-78838b0eed61
< 2.5.1
MEDIUM 6.4 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
98e22884-f7d6-47df-9b1b-9232c48e3685
< 2.5
MEDIUM 6.4 The URL Params plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versio… wordfence
98e1468e-b36a-426c-aa9e-f086c052d645
< 1.1.5
MEDIUM 6.4 The Meks Smart Author Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
98df96ad-32ef-44e2-8dc1-e7c38e3f9c74
< 3.2.1
MEDIUM 6.4 The Sprout Clients plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3… wordfence
98de0a50-8464-4ea6-bf55-add9aab2d716
< 1.08
MEDIUM 6.4 The HTML5 chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'HTML5CHAT' shortcode … wordfence
98d3aa11-346e-4e1f-9c52-3b21b77b52e6
< 1.2.70
MEDIUM 6.4 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordP… wordfence
98c3762b-9dcd-4931-846e-3f54fe2bf5e2 MEDIUM 6.4 The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'islamicDB-roqya' shortco… wordfence
98bff131-dee2-4549-9167-69dc3f8d6b9d
< 1.8.4
MEDIUM 6.4 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
98aed079-672c-43bb-a5eb-faf8ffc04b71
< 2.6.10
MEDIUM 6.4 The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit - Countdow… wordfence
98acac5c-65d7-4aaf-adcc-a58515c28fc3
< 3.7.19
MEDIUM 6.4 In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names. wordfence
988bc04a-9294-4433-b4b2-d7ccf2e08297
< 1.8.3
MEDIUM 6.4 The ANAC XML Viewer plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includi… wordfence
988a7d0a-72d2-4962-bcb4-b08859de925c
< 1.3.5
MEDIUM 6.4 The HIPAA Compliant Forms with Drag’n’Drop HIPAA Form Builder. Sign HIPAA documents plugin for WordPress is vulnerab… wordfence
987dcb6e-0f58-484f-9e9d-5ac721c145ca
< 1.3.0
MEDIUM 6.4 The Gold Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, a… wordfence
98536f33-eb3d-4b2f-bda3-97f8cf9e5b19 MEDIUM 6.4 The Tailored Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
← Prev 589 590 591 592 593 594 595 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top