🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 594 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9755e5d4-dbf6-4778-84d6-cc967e8afb48
< 1.2
MEDIUM 6.4 The Plethora Plugins Tabs + Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the anchor … wordfence
9755323f-42bd-491d-8d82-b1905eed0d9b
< 1.3.3
MEDIUM 6.4 The WEN Responsive Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
9751da30-abc7-466d-8990-4eefe65cb878
< 2.1.43
MEDIUM 6.4 The Premium Blocks – Gutenberg Blocks for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
974f6e3f-9d47-4753-a826-261d5b71651c
< 2.3.1
MEDIUM 6.4 The Buying Buddy IDX CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
974a3228-5eab-41be-b3c1-82e71cde8de7 MEDIUM 6.4 The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in … wordfence
9746cd9f-afb2-41b2-9e31-7c77222d9cfd
< 2.4.44
MEDIUM 6.4 The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact fo… wordfence
972fba75-8230-4991-a697-34ab850ddee5
< 2.1.5.1
MEDIUM 6.4 The Wholesale Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'role' parameters in versi… wordfence
9729ccc9-e3f1-4096-8430-22998b386cec
< 8.4
MEDIUM 6.4 The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pos… wordfence
97215c69-e371-48b6-9282-6241f9b187c8 MEDIUM 6.4 The RS Elements Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
97108ad1-c7b8-4050-ba0d-7a1fd4bdedb3
< 1.5.8
MEDIUM 6.4 The “Elementor – Header, Footer & Blocks Template” WordPress Plugin before 1.5.8 has two widgets that are vulnerab… wordfence
970826cf-316d-4fce-ac90-bf338c5ef3e4
< 3.1.0
MEDIUM 6.4 The Sell Tickets Online – TicketSource Ticket Shop for WordPress plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
9700a21e-19cb-4ba9-8bc1-3fb11187152c
< 2.8.120
MEDIUM 6.4 The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable t… wordfence
96fb8398-d566-439c-8ed0-78e71276b577
< 1.81
MEDIUM 6.4 The iCalendrier plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.80… wordfence
96f63469-d05d-4c7a-8fc6-165c361a7c82
< 1.3.1
MEDIUM 6.4 The Social Media Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'patreon'… wordfence
96eba67c-58e7-4eea-84d4-9b3bb275b42d
< 1.0.218
MEDIUM 6.4 The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘te… wordfence
96defcb7-6af1-4fb8-9fa0-231c6776bbc1
< 2.1.8
MEDIUM 6.4 The Anchor Episodes Index (Spotify for Podcasters) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
96dbf90d-2db9-4bfd-8110-dbe322a690bc
< 1.5.1
MEDIUM 6.4 The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
96dadf30-a66f-476c-8baf-d6e21a76185a
< 1.6.3
MEDIUM 6.4 The PDF Generator for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to,… wordfence
96bdd465-e4ca-4a32-b38a-a2a51598a3a9
< 8.3.6
MEDIUM 6.4 The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘carousel_s… wordfence
96a7ebcb-3420-497c-80e6-54e42afe41a3
< 1.1.18
MEDIUM 6.4 The WP Responsive Tabs horizontal vertical and accordion Tabs plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
96a0c18f-ddd7-4cae-bc61-c8fbf4cc3e66 MEDIUM 6.4 The Theme Junkie Team Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
9696fae6-39fe-4478-90e7-488b5b573fa8
< 4.9.1
MEDIUM 6.4 The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) plugin for WordPress… wordfence
9694fae8-dfe9-4e19-bebc-2f2a607cff82
< 3.5.0
MEDIUM 6.4 The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versi… wordfence
968dce76-783a-4c1a-8d62-e1f8d6cc2f2c MEDIUM 6.4 The EZPlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.10 … wordfence
9681ecf9-e020-4b3a-ad31-f8f203d548aa MEDIUM 6.4 The Rollover Tab plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3… wordfence
← Prev 591 592 593 594 595 596 597 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top