πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 598 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
93be1150-4c83-4fa3-8dc6-71e2f1ddaa66 MEDIUM 6.4 The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'publicationid' attri… wordfence
93b83e65-09d6-4ad5-85f3-d18a9a35f39d
< 3.4.2
MEDIUM 6.4 The Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder plugin for WordPress is v… wordfence
93b53241-6556-4a67-97e6-ea30f3c4ef76 MEDIUM 6.4 The Drift theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and… wordfence
93ab3e05-dbaf-4f55-a411-793a74c75071 MEDIUM 6.4 The Inline Stock Quotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock shortco… wordfence
93920201-fd53-45ad-983a-a2b04b96db77
< 1.3.9
MEDIUM 6.4 The Icegram Collect plugin for WordPress is vulnerable to Cross-Site Scripting via the 'rainmaker_form' shortcode in ver… wordfence
93898bf8-cfed-44bf-9d68-a0167beba86a
< 5.1.4
MEDIUM 6.4 The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'w… wordfence
938852c9-bc9b-4215-9e6b-9af122d1e8e7
< 2.5.17
MEDIUM 6.4 The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.… wordfence
93818487-739e-48ed-ac67-02469277c22d MEDIUM 6.4 The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u… wordfence
9379e1c9-fb83-43e4-af89-898dc0c2216c
< 3.8.0
MEDIUM 6.4 The Event Manager and Tickets Selling Plugin for WooCommerce is vulnerable to Stored Cross-Site Scripting via the plugin… wordfence
93698608-eda1-4479-8089-5b6ed7ed7607 MEDIUM 6.4 The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
9363b671-edc5-4699-b536-0b42917b27ba MEDIUM 6.4 The External Media plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin… wordfence
93635e8c-930d-4074-a32f-198145ebbd43 MEDIUM 6.4 The 360 View plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.0 d… wordfence
935b5620-40d8-40ef-99f3-260e6f49f84c MEDIUM 6.4 The Series plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.1 due… wordfence
935054c3-8541-4ff3-a035-7ee8afe53f72
< 1.3.9
MEDIUM 6.4 The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s… wordfence
934db08b-7dde-43bf-848b-48fba38ef195
< 1.0.14
MEDIUM 6.4 The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod… wordfence
934bf839-152d-4d10-9ac8-c64cf042dc18
< 2.6.4
MEDIUM 6.4 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sto… wordfence
9349208c-3e86-4ec6-9e10-5ecaa4923922
< 2.6.4
MEDIUM 6.4 The Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Caro… wordfence
93427a3a-8cbe-4aa7-93e2-c6807bc3390c
< 1.1.25
MEDIUM 6.4 The Easy Contact Form Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
932ba486-d98d-4c16-afe5-3aaf030a1e48
< 5.5.4
MEDIUM 6.4 The Element Pack Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link URL in … wordfence
930802e6-437b-437a-b530-7992094073f9
< 1.9.1
MEDIUM 6.4 The WP GeoNames plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-geonames' shortco… wordfence
93029d39-adaa-4cf6-9081-28c9e84ec2e5
< 1.2.1
MEDIUM 6.4 The MF Gig Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event's time and title pa… wordfence
9300af5d-7886-4f4e-8454-0dcf2d895fee MEDIUM 6.4 The Photographers galleries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcode att… wordfence
92ffaa23-08f2-4aa4-84c3-a84c26ed8474
< 5.0
MEDIUM 6.4 The Image Hover Effects For WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
92f8e3b7-a896-494b-96cd-6ecb8918ebd6
< 4.7
MEDIUM 6.4 The Albo Pretorio Online plugin for WordPress is vulnerable to Stored Cross-Site Scripting parameter in versions up to, … wordfence
92f53507-4475-401b-b57c-f6652a868be9 MEDIUM 6.4 The Cute News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribu… wordfence
← Prev 595 596 597 598 599 600 601 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top