πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 595 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
96769a0e-d4a9-4196-8ded-b600046c0943
< 7.0.4
MEDIUM 6.4 The WP Shortcodes Plugin β€” Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
967201a0-a47f-497e-a062-d6c60e1edb86
< 2.8.3.9
MEDIUM 6.4 The Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
965cd061-d34e-4749-85a6-efa2456b1446 MEDIUM 6.4 The Adventure Journal theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includ… wordfence
965cacd3-1786-4e7d-8209-eea293b161d3
< 3.2.2
MEDIUM 6.4 The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜… wordfence
9649b153-3acc-4e5b-9338-448099aba887 MEDIUM 6.4 The Medical Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
963db13e-14aa-4fc0-8d28-3f8a22361361 MEDIUM 6.4 Testimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user in… wordfence
96161594-9513-49f7-91ab-9ad05b900a81
< 3.8.3
MEDIUM 6.4 The UberMenu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ubermenu-col, ubermenu_m… wordfence
96140bf6-d1fc-4eb5-aaf5-4bd6a6ebdee7 MEDIUM 6.4 The Patterns Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0… wordfence
96086886-72f4-4a62-8f31-fc20e5240ba4
< 2.7.4.3
MEDIUM 6.4 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
95fa3158-9add-4fed-b9ff-7442f74ba70c
< 2.4.0
MEDIUM 6.4 The Templatera plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.0… wordfence
95e18a52-a027-413d-b21d-df5518f23308 MEDIUM 6.4 The Elementor Portfolio Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
95ded4bf-9964-4bb3-b6e5-5ad37360f87d
< 6.4.7.2
MEDIUM 6.4 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
95d8b7c8-55c2-4760-aaf3-47fc5b43fc9c
< 3.5.4.1
MEDIUM 6.4 The WP-Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.4… wordfence
95d61096-8e44-4b70-a409-c02cb3d1e32c
< 2.15.5
MEDIUM 6.4 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
95d3e76c-612d-436c-9d32-6228d7dcbf35
< 51.1.54
MEDIUM 6.4 The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Sc… wordfence
95d0d6a1-a3d3-4792-bdf6-e07db83d646c MEDIUM 6.4 The Marketer Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
95d06679-a603-45c4-840f-e38a7cd0c739 MEDIUM 6.4 The Genealogical Tree plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
95ce515a-377c-49b4-8d1b-7ac22769c759
< 1.5.11
MEDIUM 6.4 The Interactive Geo Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the action content parame… wordfence
95cb355f-0f3a-4eb1-b218-e6b0c457d0e7 MEDIUM 6.4 The Justified Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
95c7f999-3676-4b91-9ee0-f55a27bcd93c MEDIUM 6.4 The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_ac… wordfence
95c5bfc5-53b3-482f-856b-db6b6cac93a2
< 3.3.9
MEDIUM 6.4 The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stor… wordfence
95c262b6-4f63-4f81-bc73-b2b3fa586a21
< 2.6.0
MEDIUM 6.4 The Slideshow SE plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5… wordfence
95ba48b9-4a9c-47df-b05e-e670ae547810
< 3.8.7
MEDIUM 6.4 The Social Media Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versio… wordfence
95b727ee-b410-471b-98f2-7cebd7f64a58
< 1.4.7
MEDIUM 6.4 The News Kit Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Site Logo Title … wordfence
95acec2a-ba1b-4b61-a4d6-3b0250a32835
< 2.4.7
MEDIUM 6.4 The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
← Prev 592 593 594 595 596 597 598 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top