πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 608 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
89ddede9-3170-48bb-aae5-14f915330f67
< 2.0.6
MEDIUM 6.4 The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
89cb81c3-25d7-4a4e-beed-558ea8ce721d
< 0.7.1
MEDIUM 6.4 The Orange Confort+ accessibility toolbar for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
89bdd732-a9ee-4ab8-a70e-195b92142fe1
< 4.0.10
MEDIUM 6.4 The Video Conferencing with Zoom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in vers… wordfence
89acb513-60aa-49ad-8050-9dff1ce71cc5
< 2.4
MEDIUM 6.4 The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
89a15f3d-8aa7-4f74-841e-f53347c02dc5 MEDIUM 6.4 The Page Builder Sandwich – Front-End Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… wordfence
8996a0f0-8a49-4310-917b-62172c12afdb
< 9.112.2
MEDIUM 6.4 The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_veu_custom_… wordfence
8981ab1d-5957-444c-a5f1-57317a2e8395
< 1.2.8
MEDIUM 6.4 The MyAlice – Live Chat, WhatsApp, Facebook Messenger, Instagram, & Chatbot for WooCommerce plugin for WordPress is vu… wordfence
897fcc35-b700-4699-acd0-04a271686498 MEDIUM 6.4 The Postify: Post Layout For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
897f8459-b998-46f9-8429-aeffb71b93c7 MEDIUM 6.4 The ContentBot AI Writer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
897f42da-cbe4-4a43-abc0-659bb9cda7a0
< 1.7
MEDIUM 6.4 The SKT Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6 d… wordfence
8972e095-e478-4a3a-bfa9-a63128d1f6bf MEDIUM 6.4 The WP Publication Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
895e9ead-14d8-432b-81dd-4d292eee462a
< 3.0.16
MEDIUM 6.4 Stored XSS in Salutation Responsive WordPress + BuddyPress Theme version 3.0.15 could allow logged-in users to do almost… wordfence
895d882b-f4ca-4837-9d8e-aca04c3fb9e3
< 2.6.1
MEDIUM 6.4 The Page View Count plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in ver… wordfence
8955456c-c356-4e72-87d2-2ffa910c6808 MEDIUM 6.4 The Opal Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
89525af0-105a-4d7d-93d1-af724a837e7a
< 1.4.2
MEDIUM 6.4 The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to Stored Cross… wordfence
89512190-a0fe-495a-9dda-8d8540a5325c MEDIUM 6.4 The Connatix Video Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cnx_script_… wordfence
89409461-c87e-4882-bf53-cc789e459b4f MEDIUM 6.4 The Wp-D3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up… wordfence
893fa8c6-dcb4-4613-a836-8c717f859696 MEDIUM 6.4 The WowPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wowpress` shortcode in … wordfence
8910b6f0-1bf4-4ac0-93b7-54db7c15392c
< 2.0.5.7
MEDIUM 6.4 The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Table … wordfence
890ac1f4-6003-428f-a4d3-123d6a4994b5 MEDIUM 6.4 The LeadQuizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.… wordfence
88f4af1b-5e3c-4129-93c3-4f368bd2b0db MEDIUM 6.4 The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver… wordfence
88f2fa28-5bb2-4633-b2bc-27cc6a4e304c
< 2.3.5
MEDIUM 6.4 The Easy Accordion – Best Accordion FAQ Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
88e74cb2-7b6f-43ac-bb30-4763c5afe493
< 1.13.14
MEDIUM 6.4 The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's geo_mashup_visible_pos… wordfence
88e4eec2-2861-4d1d-97eb-67887f59c745
< 5.94.0
MEDIUM 6.4 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'displayN… wordfence
88d769cd-bea8-42e4-80a8-a77c0699b50c
< 3.2.22
MEDIUM 6.4 The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonial_v… wordfence
← Prev 605 606 607 608 609 610 611 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top