πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 612 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
86068c50-2f24-4af9-a20f-704d52e98ce2
< 5.7.3
MEDIUM 6.4 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… wordfence
8603d4cd-5e01-4a68-b127-8c99609e0413
< 4.0.1
MEDIUM 6.4 The Zoho Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0 d… wordfence
85e0e1c5-211f-434c-8cc8-1ca676a8c7c2 MEDIUM 6.4 The Preloader Plus – WordPress Loading Screen Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
85c7af8b-31d4-4672-a857-da0e39c1c803
< 3.8.12
MEDIUM 6.4 The JetEngine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.… wordfence
85c123ee-8de0-4800-b96b-68bb4d763560
< 1.2.2
MEDIUM 6.4 The Able Player, accessible HTML5 media player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
85bf7a1b-3c54-40c9-8f19-fcb9dd478a0e
< 20260113
MEDIUM 6.4 The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Store… wordfence
85afaef5-e19d-4052-ba72-89518f33b462 MEDIUM 6.4 The Clever Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
85a94f32-e1e5-48ea-822e-c54d0592da28
< 3.6.2
MEDIUM 6.4 The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all v… wordfence
85950e4c-59fe-4ad3-8c43-e161259d6ded MEDIUM 6.4 The Pathomation plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.… wordfence
8588f9e8-441c-4b9e-bd78-8526d8c28fa3
< 4.6.10
MEDIUM 6.4 The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco… wordfence
857ed49c-8d0f-44d6-a97b-d0bc142dd43f
< 1.2.39
MEDIUM 6.4 The Magical Posts Display – Elementor & Gutenberg Posts Blocks plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
856a6b88-f5fc-4b87-8a94-81e233f02e2f
< 3.7.5
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3… wordfence
855ef024-98a6-4afb-acc8-1b6677ffd433 MEDIUM 6.4 The bpmn.io plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 due … wordfence
855ae993-d887-4416-9b3c-8274a90dce5f
< 6.1.13
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for … wordfence
8559690a-3cae-47c5-b2fe-521365541126
< 1.9.35
MEDIUM 6.4 The WooCommerce Designer Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
85551ba1-6d6e-47a0-864f-f9d0a0a11056
< 2.9.14
MEDIUM 6.4 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to stored Cross-Site Scripting via… wordfence
8540b8f3-aace-4559-b83c-6244f2249548
< 9.8
MEDIUM 6.4 The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortc… wordfence
853b86ca-0231-4b1c-b1d2-b8c23dbdc3c5 MEDIUM 6.4 The Gutenify – Visual Site Builder Blocks & Site Templates. plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
8536e655-72cc-4d7a-8ca0-7ba3042e03c1 MEDIUM 6.4 The Easy Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3… wordfence
85281c48-d427-49c4-95aa-420eb328e798
< 10.3.2
MEDIUM 6.4 The SmartMag theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 10.3.1 d… wordfence
85216580-f19e-4e69-93d9-8593b8524cdc
< 4.3000000025
MEDIUM 6.4 The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
85201c44-34a9-4995-a162-242dfe703934
< 1.8.1
MEDIUM 6.4 The Cooked – Recipe Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'coo… wordfence
851bade8-bd3a-4fb1-8a1d-12461287694e MEDIUM 6.4 The TCBD Auto Refresher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd_auto_re… wordfence
85150a6f-b2f3-4b95-9c9b-78f50cb8468f
< 3.3.3
MEDIUM 6.4 The XO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to… wordfence
8512cc6b-d2a4-4436-81b8-2745cd4e6063
< 1.3.3
MEDIUM 6.4 The Gallery PhotoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
← Prev 609 610 611 612 613 614 615 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top