πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 599 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
92f36efb-7eaa-42bd-adca-ec2d626d52aa
< 2.1.2
MEDIUM 6.4 The The Pack Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
92ea6a89-b14f-4252-b886-e219c1bb658d
< 1.9.3.2
MEDIUM 6.4 The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress i… wordfence
92daf977-1b60-4ecf-b3bc-e8d356b4e0b7
< 2.7.3
MEDIUM 6.4 The GutSlider – All in One Block Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
92d106c6-a910-4f41-94d1-59f6b7f3aeb0
< 3.10.2.2
MEDIUM 6.4 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
92c1bd85-5f81-4bb6-b6af-6cda85b91b9e
< 4.7.4
MEDIUM 6.4 The WPML plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpml_language_switcher short… wordfence
92c072d0-92de-4189-8ccd-c8d9b748855b MEDIUM 6.4 The Ibtana plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.4.9 d… wordfence
92bcdbd9-1f41-4990-9bea-587fb0e7355a MEDIUM 6.4 The Owl Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and … wordfence
92ae41bb-fc9a-486f-937d-e755b7f840fe MEDIUM 6.4 The Tiger theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0 due to … wordfence
92aae1f6-e624-4619-8195-ee3c443a31fc MEDIUM 6.4 The Donations Made Easy – Smart Donations plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
92a81d4a-58ed-4812-a1f8-db86e410393c MEDIUM 6.4 The Posts By Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2… wordfence
929ec66c-a4b2-4846-8330-65fd0e595e58
< 3.72
MEDIUM 6.4 The 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin plugin for WordPress is vulnerable to St… wordfence
929bc383-cafc-4f70-9589-b630756b1143 MEDIUM 6.4 The rajce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.4.2.… wordfence
92967cd6-3619-4892-b481-75a35a0f2c33 MEDIUM 6.4 The Redirecter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 d… wordfence
929085b2-3038-41d1-bd61-ce9e7dc79f78
< 1.2.7
MEDIUM 6.4 The Gallery PhotoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
9290532f-58d7-4e7d-9fa0-89c7f82b0466
< 4.5
MEDIUM 6.4 The Social Share Boost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ssboost shortcode in ve… wordfence
9289e93c-22ac-4f3f-8a8a-591d9a598713
< 1.6.2
MEDIUM 6.4 The Schema Scalpel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions … wordfence
926646de-4fb0-4460-b0d1-4d451e6505ca
< 2.1.0
MEDIUM 6.4 The WP Wiki Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wiki' shortcode … wordfence
926201d1-36bd-451f-a433-862e0484b36d
< 2.3.1
MEDIUM 6.4 The bunny.net plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.0 … wordfence
925b0a86-ed23-471c-84e2-ae78a01b1876
< 2.6.9
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Anythi… wordfence
924b6413-79f2-4f8f-8d73-74dbfb48550c
< 4.2.0
MEDIUM 6.4 The LearnPress – Course Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
923f9e66-2e26-4ec2-a4b3-439881a6ca10
< 2.7.32
MEDIUM 6.4 The Lightbox & Modal Popup WordPress Plugin – FooBox plugin for WordPress is vulnerable to DOM-based Stored Cross-Site… wordfence
923c51ba-0ec2-4e32-a86e-404f3fe2ac7c
< 4.4.7
MEDIUM 6.4 The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `… wordfence
92313cda-5e93-4c25-93f3-d0c23f30d290
< 2.4.2
MEDIUM 6.4 The Void Contact Form 7 Widget For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
921be7ff-3d38-4b69-8a1f-a64d5aabd2dd
< 2.8.3
MEDIUM 6.4 The XT Floating Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo… wordfence
92187edb-6388-45c0-b97f-16e83bb685f1
< 3.7.2
MEDIUM 6.4 The SyntaxHighlighter Evolved plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
← Prev 596 597 598 599 600 601 602 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top