🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 600 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
921be7ff-3d38-4b69-8a1f-a64d5aabd2dd
< 2.8.3
MEDIUM 6.4 The XT Floating Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo… wordfence
92187edb-6388-45c0-b97f-16e83bb685f1
< 3.7.2
MEDIUM 6.4 The SyntaxHighlighter Evolved plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
92180939-eae9-4b8f-9fa3-cd8e79b71291
< 5.3.2
MEDIUM 6.4 The FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor plugin for Wo… wordfence
92175fc7-4880-47d4-96fa-ecbe15f61fb0
< 1.6.4
MEDIUM 6.4 The Structured Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
921616e4-2b66-4847-869a-90c1c459685f
< 2.4.31
MEDIUM 6.4 The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Imag… wordfence
920dbe31-ccbd-4ad9-9c5f-f7389c1b4318 MEDIUM 6.4 The CPO Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
92084af7-142b-45de-8881-dee5cf1367e2 MEDIUM 6.4 The Video.js – HTML5 Video Player for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
91f93b13-528b-42f5-9b3b-edc84d7ae3d4
< 1.09
MEDIUM 6.4 The Child Pages Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
91f6c9d3-641d-42f7-bf11-e3c3a44eeb76
< 1.23.2
MEDIUM 6.4 The Simple Cloudflare Turnstile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gravity-simple-tu… wordfence
91f50b65-f001-4c73-bfe3-1aed3fc10d26
< 5.9.20
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
91f45973-5a98-4fdd-88fd-83b95f6d77e7 MEDIUM 6.4 The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linkgate' … wordfence
91e7afef-8e43-400e-a0ed-a2b5f1fc7b6d MEDIUM 6.4 The Anant Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
91ddc368-bfe5-4581-aa99-ac9f4bcf9da4 MEDIUM 6.4 The Epic Bootstrap Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘icol’ paramete… wordfence
91d6cf21-cb65-40cb-ad19-5a8e7179fd98
< 4.8.8
MEDIUM 6.4 The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulne… wordfence
91d1c81d-cf06-45db-a868-8f1c6ba3ccc9 MEDIUM 6.4 The Awesome Tool Tip plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
91d12259-a611-4921-ba03-eb9221ef49fd MEDIUM 6.4 The Demo User DZS – Showcase your admin safely plugin for WordPress is vulnerable to Stored Cross-Site Scripting in al… wordfence
91c87d34-ef9a-42f4-b11a-7c5a5c842550 MEDIUM 6.4 The Mosaic Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘c’ parameter in all … wordfence
91ba2c79-ac70-4bb2-b687-65db27469557 MEDIUM 6.4 The FancyPost plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.0.1 … wordfence
91a9dcf2-ba6b-4d03-9cdf-f50ea0d259d8
< 1.4.1
MEDIUM 6.4 The Panda Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all vers… wordfence
91a8721e-de2d-45db-85a8-1b65f7b38892
< 1.3.19
MEDIUM 6.4 The JetBlocks For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
916cf0df-31ab-4f99-82d1-e1e30f5f8c6f
< 1.8.8.1
MEDIUM 6.4 The Fluida theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.8 due … wordfence
916a9d2b-0da6-494a-a3aa-5d5f4ccdd4b8
< 2.3.10
MEDIUM 6.4 The “All-in-One Addons for Elementor – WidgetKit” WordPress Plugin before 2.3.10 has several widgets that are vuln… wordfence
915f464f-449d-4ad2-9f43-6ce5d93ccb05
< 3.5.1.23
MEDIUM 6.4 The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
915c46f9-a342-4cc6-a726-2f1581a5d481
< 4.9.9.5
MEDIUM 6.4 The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's newsletters_video sho… wordfence
915c119d-2bae-4ea6-babb-7e8e99054cd0
< 2.0.9
MEDIUM 6.4 The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Cu… wordfence
← Prev 597 598 599 600 601 602 603 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top