🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 611 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
86fbc499-dca3-41da-a6ef-8e97d7e46d0e
< 2.8
MEDIUM 6.4 The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
86e8e16f-9d93-457a-9093-2fd236e51682
< 4.7
MEDIUM 6.4 The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's … wordfence
86e62a7d-53d6-40c8-823d-811cfb3d75b2
< 3.23.0
MEDIUM 6.4 The YouTube Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in ver… wordfence
86dfdc4f-1cc2-4b0d-b79c-bee3d6956eb4
< 2.5.6
MEDIUM 6.4 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via mult… wordfence
86cf664f-5de1-4692-96b3-2fd8ae35110b
< 4.8.9
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tags in all versions up… wordfence
86cee705-6874-4fcc-b13c-bd20f6e0704b
< 1.9.7
MEDIUM 6.4 The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could… wordfence
86c4e138-0ef1-46b4-b925-e82e18c30835
< 2.20.4
MEDIUM 6.4 The VK Filter Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
86c0f530-bf4c-4de4-84db-e8469cea76c5
< 3.4.0
MEDIUM 6.4 The Woocommerce CSV importer plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and includ… wordfence
86b655a6-7d71-441a-8430-6e72aecb37d8 MEDIUM 6.4 The Simple Google Static Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
86b21472-6a76-4d7b-84ff-f8b79c052aba MEDIUM 6.4 The Drive Folder Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tablecssclass’ … wordfence
86a41cdf-8d7a-4d62-9370-8bdf4a259819
< 2.5.1
MEDIUM 6.4 The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up t… wordfence
86a3dd1b-49cd-467b-b826-d906d9fb775f
< 1.0.6
MEDIUM 6.4 The Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating plugin for WordPress is vulnerable to Stored … wordfence
865ff4bf-608e-45f0-a160-35581b82cc2b MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid component in a… wordfence
8657003f-da37-4169-9f00-262d7f3d9a9c
< 5.6.2
MEDIUM 6.4 The iThemes Security for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up t… wordfence
8640724c-0bd4-4684-9fd1-027f2af64e67 MEDIUM 6.4 The Easy Social Photos Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper_class'… wordfence
863d59d5-ae74-4fc7-82fb-3039743af4b8 MEDIUM 6.4 The Mixtape plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mixtape' shortcode in al… wordfence
863c8d7f-106a-40e5-a679-a796225569ae MEDIUM 6.4 The Multifox theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.7 du… wordfence
863c4897-d61a-4f38-97c9-ec6113d47678
< 1.0.15
MEDIUM 6.4 The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
86374310-748e-4adb-9d6f-6442fbb921be MEDIUM 6.4 The Easy Tweet Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
86364b6f-dec8-48d8-9d2d-de1ee4901872
< 4.5.2
MEDIUM 6.4 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Store… wordfence
86301ef6-28b8-4831-b542-6aae33f705ea MEDIUM 6.4 The Genesis Style Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
86276cc4-635d-4bb8-93b2-75ce3fab0f90
< 2.7.8
MEDIUM 6.4 The Brizy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.7 due … wordfence
861d0218-0f0f-4299-a0ff-854832348457
< 5.9
MEDIUM 6.4 The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cro… wordfence
86068c50-2f24-4af9-a20f-704d52e98ce2
< 5.7.3
MEDIUM 6.4 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… wordfence
8603d4cd-5e01-4a68-b127-8c99609e0413
< 4.0.1
MEDIUM 6.4 The Zoho Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0 d… wordfence
← Prev 608 609 610 611 612 613 614 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top