πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 602 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
908e4755-e439-4714-b0cb-3fc546c5ac63
< 1.6.3
MEDIUM 6.4 The Structured Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
9087b16e-488b-431d-a7f7-ab0d49520756
< 2.3.9
MEDIUM 6.4 The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise som… wordfence
90654fac-b9c7-422f-8472-2a7c7fd0de0d
< 8.0.4
MEDIUM 6.4 The Quick Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via parameters like 'tab', 'sen… wordfence
906049c0-4710-47aa-bf44-cdf29032dc1f
< 2.25.27
MEDIUM 6.4 The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho… wordfence
90579442-b05c-459e-93cb-f4883b6472ff
< 2.9.1
MEDIUM 6.4 The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cro… wordfence
90503670-702f-4113-9887-61558bf7ea5c
< 1.47.2
MEDIUM 6.4 The Newspack Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4… wordfence
904ba3ec-efde-424c-a50b-2ce71ad91ca5 MEDIUM 6.4 The Supreme Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
904a7751-fbf6-47a7-8b68-87f1f042c89c
< 4.14.2
MEDIUM 6.4 The UDesign Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1… wordfence
90411c04-8d5b-4d9d-9beb-ef8374b31bb3
< 3.2.3
MEDIUM 6.4 The Wishlist for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
902c0c84-fcae-4ce4-9885-89fd135a4ffd
< 4.12.3
MEDIUM 6.4 The Cloudflare plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th… wordfence
90284576-6570-4e4c-8eb3-743bc402ea1b
< 0.13.14
MEDIUM 6.4 wordfence
901354c7-a908-4014-aee2-085892f4e4d6
< 1.3.18
MEDIUM 6.4 The ARI Fancy Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
9002fe5c-d7c7-4d4a-9e92-db6ff390d78b
< 14.0
MEDIUM 6.4 The Vertical scroll recent post WordPress plugin before 14.0 does not sanitise and escape a parameter before outputting … wordfence
8ffb789a-409f-4771-a5e1-2643b6aeadf8
< 1.5.8
MEDIUM 6.4 The Primary Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
8ff92ea9-a9d9-4d74-b91e-44ecb19c59f8
< 2.15.1
MEDIUM 6.4 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ… wordfence
8fef8676-8bf7-495f-a134-497756f329f2
< 4.0.10
MEDIUM 6.4 The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
8fd93a48-72ab-4475-a25d-d68c98939533
< 4.4.0
MEDIUM 6.4 The Essential Real Estate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'font[0][selector]' … wordfence
8fcb4047-5173-4d10-a4bb-72f1919b9203
< 3.0.2
MEDIUM 6.4 The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu… wordfence
8fa3bcb9-df3e-4042-a28b-3d09bfebeebc
< 3.8.8.1
MEDIUM 6.4 The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attri… wordfence
8fa2e98b-5054-46fd-b22e-eac59b581a3c
< 1.2.4
MEDIUM 6.4 The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headerHtmlTag' attribu… wordfence
8f7ce513-45ba-427b-8ee0-1007e404c1a9 MEDIUM 6.4 The Login Logout Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter i… wordfence
8f6e6fcb-1688-424e-b0fa-1c0ace474c2c MEDIUM 6.4 The Percent to Infograph plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `percent_to_graph` sh… wordfence
8f5b9aff-0833-4887-ae59-df5bc88c7f91
< 4.4.4
MEDIUM 6.4 The Social Sharing Plugin - Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social… wordfence
8f59e069-a953-47b6-8106-55f55df722ed
< 4.2.2
MEDIUM 6.4 The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'other_attributes… wordfence
8f551441-1f41-4ae2-93a7-6385fa3a70e3 MEDIUM 6.4 The Kimili Flash Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
← Prev 599 600 601 602 603 604 605 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top