πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 610 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
87da5300-1add-44fc-a3e0-e8912f946c84
< 7.9.0
MEDIUM 6.4 The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in … wordfence
87d4c2f5-d285-4063-af97-d060ae8496d8
< 6.4.1
MEDIUM 6.4 The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
87d228bb-eb5b-44ca-91f7-ada730635a3f
< 1.0.3
MEDIUM 6.4 The Buy Now Plus – Buy Now buttons for Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
87cc821c-21d5-49b7-9b72-030ca016efd8 MEDIUM 6.4 The Share to Google Classroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the share_to_google … wordfence
87ca07ac-6080-45d7-a8f5-74a918adec43
< 7.11.7
MEDIUM 6.4 The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery… wordfence
87944086-a4a4-4152-99f1-847eef7569ea
< 3.3.6
MEDIUM 6.4 The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via title tags… wordfence
879384eb-bfea-4667-a7de-9f723dbea74b
< 2.3.2
MEDIUM 6.4 The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in al… wordfence
877a42c9-958d-46ed-8f9a-5972bd5f43f8
< 2.9.3
MEDIUM 6.4 A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 … wordfence
8774f448-ba63-428c-8a82-b229718fdd10
< 2.3.12
MEDIUM 6.4 The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a s… wordfence
8772a00a-b285-4b1e-a903-6f8404cf21a3
< 1.4.0
MEDIUM 6.4 The Login Logout Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to,… wordfence
876f9c76-dc4f-4d79-a037-43304245df32
< 13.8
MEDIUM 6.4 The Jetpack plugin for WordPress, versions less than and equal to 13.7, and the Jetpack Boost plugin for WordPress, vers… wordfence
876b57e0-cf1e-4ce9-ba85-a5d4554797bd
< 2.11.1
MEDIUM 6.4 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for… wordfence
87672771-585b-41ca-a274-5bd6f8401ff3
< 1.3.18
MEDIUM 6.4 The Walker Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.… wordfence
8761c046-35da-4fc9-a839-c06405ff4b31 MEDIUM 6.4 The All Social Share Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sc' sho… wordfence
875db71d-c799-40b9-95e1-74d53046b0a9
< 5.9.8
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
8746b363-f1c2-42cb-83cf-639ab4102a50 MEDIUM 6.4 The Meks Easy Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title field in all ver… wordfence
8736fb91-d05c-4f7e-81ff-00dfa44961f5
< 3.14.2
MEDIUM 6.4 The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress i… wordfence
8736cf81-3fb8-4c81-a878-7d73a3e68fc2 MEDIUM 6.4 The Branding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up t… wordfence
87368d85-04d4-42e6-9ba6-2a1fc3b945a8
< 1.9.1
MEDIUM 6.4 The WP Last Modified Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜template’ attri… wordfence
872c8328-9089-4bc0-af17-f755524da610
< 1.7.10
MEDIUM 6.4 The WP GPX Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sgpx' shortcode in a… wordfence
871e5bb2-acda-4b57-8d9f-f7c47ee606fb MEDIUM 6.4 The RSV PDF Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
871e1be0-2dd2-47d1-b497-ca71e6f3b090 MEDIUM 6.4 The Mad Mimi for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
870beaba-5294-4a77-89d1-8d5cf92974dc
< 3.6.17
MEDIUM 6.4 The WordPress Page Builder – Zion Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
8704320e-9624-4924-92e8-adb61356aecb
< 1.0.8
MEDIUM 6.4 The URL Image Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver… wordfence
87040f2b-4de0-4a8d-ae30-b340638a6df2
< 7.36
MEDIUM 6.4 The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forg… wordfence
← Prev 607 608 609 610 611 612 613 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top