πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 593 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
98536242-64c7-4e02-aa00-a3efbf5c90d8
< 2.1.5
MEDIUM 6.4 The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg f… wordfence
985115ca-56f0-48ca-ae58-f09e1cc80046
< 10.0
MEDIUM 6.4 The Surbma | Premium WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
9841b57b-b869-4282-8781-60538f6f269f MEDIUM 6.4 The Add Custom Body Class plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_custom_body_cla… wordfence
983e8ec0-fec4-4420-8ef6-6bf43881f5f1
< 1.0.89
MEDIUM 6.4 The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl… wordfence
983e5334-85e3-476d-9f47-874a35f70177
< 2.2.5.4
MEDIUM 6.4 The SecuPress Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
983a5b15-adf7-4f34-bf2a-30857ada2753
< 5.3
MEDIUM 6.4 The Page-list plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and inc… wordfence
9820b52b-540a-47e8-9e5f-274ef1720ffa
< 3.14.8
MEDIUM 6.4 The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress i… wordfence
981639a3-63c4-4b3f-827f-4d770bd44806
< 7.1.1
MEDIUM 6.4 The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in… wordfence
97f83e6b-a0df-4ed6-a528-7243bf851c1b MEDIUM 6.4 The WP Proposals plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3… wordfence
97df0ac7-3240-4d2b-aa2c-779c8e9359e8
< 4.1.16
MEDIUM 6.4 The PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.15 due… wordfence
97ddb0e9-1bb8-48ed-9fa3-d2b5f260263b
< 5.5.64
MEDIUM 6.4 The WP Data Access plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpda_app' shortco… wordfence
97cb2707-c67a-4b2b-a7fc-8778580a5f13
< 1.3.5
MEDIUM 6.4 The Services Section block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
97c1aeee-a82e-4d09-bffb-a91a89d0ea1e
< 5.1.1
MEDIUM 6.4 The real.Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions… wordfence
97bd4897-c0c2-4819-aa25-942e256de9a3
< 2.3
MEDIUM 6.4 The Wonder Video Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wonderplugin_v… wordfence
97a1ab2f-b531-46a7-ad51-a652fc078212
< 3.2.0
MEDIUM 6.4 The Elespare – Blog, Magazine and Newspaper Addons for Elementor with Templates, Widgets, Kits, and Header/Footer Buil… wordfence
97974da8-cb02-491e-940a-3e08f94a4373 MEDIUM 6.4 The Card Elements for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
97964532-c9bd-4bc1-8f57-b2cd2c47a0e0
< 1.3.9
MEDIUM 6.4 The Pixgraphy theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3… wordfence
9790bb19-bb5c-407c-9a2f-589b8b318ffb MEDIUM 6.4 The Checklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.9 … wordfence
9788e450-4e79-43ce-ae78-466eef458c29
< 0.10.0
MEDIUM 6.4 The Integrate Firebase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'firebase_show… wordfence
97840f5f-77b8-4b89-8d3e-1d3a9b727a06 MEDIUM 6.4 The Last Updated Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
977bab12-969d-4b15-9942-2b17c8541f61
< 1.13
MEDIUM 6.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜eae_custom_ove… wordfence
97759a47-c52a-4113-86c0-453a53fb44a6
< 1.5.7
MEDIUM 6.4 The Portfolio Gallery – Image Gallery Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
97669ac1-2ff0-46f6-8709-c007476ed4a0 MEDIUM 6.4 The Scroll Top Advanced plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
97666e54-8e86-4f18-ae32-ad8ca607aeff
< 3.19.20.1
MEDIUM 6.4 The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ult_… wordfence
975e760f-c099-414b-9179-6f2a1f1358b5
< 1.8
MEDIUM 6.4 The Recurring PayPal Donations plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, … wordfence
← Prev 590 591 592 593 594 595 596 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top