πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 613 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8510aa3d-5500-4c31-aa46-c4650aeabb29
< 1.4.4
MEDIUM 6.4 The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.3 … wordfence
8500ac5b-44e6-47b9-ab16-e7636c3fea66 MEDIUM 6.4 The GF Custom Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio… wordfence
84ff7fa7-c005-4a3d-b8b8-c251275b0653 MEDIUM 6.4 The EventPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.0… wordfence
84fdd899-46d9-4778-bd88-8df8f2f9e540 MEDIUM 6.4 The Yet Another Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
84ef25b6-8119-41e5-9959-ccdfb9893e75 MEDIUM 6.4 The Awesome buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn2 shortcode in… wordfence
84e6bd88-88d1-4529-86f3-6c73fb47db9b
< 1.0.3
MEDIUM 6.4 The Orbisius Random Name Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_label'… wordfence
84ddb481-f989-4ba8-9925-e8327c30de38
< 6.8
MEDIUM 6.4 The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vuln… wordfence
84ce21b9-91ac-4990-8665-69a1461147ab
< 2.5.31
MEDIUM 6.4 The Flash & HTML5 Video plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on s… wordfence
84cb907c-bd6b-4031-96a1-8a6de71923e0
< 1.2.2
MEDIUM 6.4 The WPZOOM Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in ve… wordfence
84c79b0e-01d2-4710-9a02-edceab8db22d
< 3.2.2
MEDIUM 6.4 The Scriptless Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's class b… wordfence
84c74c68-619f-4372-8abe-36c1b8eca858
< 1.2.7
MEDIUM 6.4 The ColorNews theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.6 d… wordfence
84bc611c-c38a-4282-9a9b-5bb9157fb1de
< 2.2.81
MEDIUM 6.4 The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordP… wordfence
84b6f093-afd4-401f-ba82-d5be10b0fff8 MEDIUM 6.4 The AI Twitter Feeds (Twitter widget & shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in v… wordfence
84adbde0-9a9b-4a76-9333-56880fcc139d
< 1.0.7
MEDIUM 6.4 The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trafftbook… wordfence
84a63e2b-4842-4132-ae56-f9ef4fbaf06a
< 1.0.17
MEDIUM 6.4 The X Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
8494c3b1-350e-4d78-9acb-9d5e876e4ab1 MEDIUM 6.4 The FontAwesome.io ShortCodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
84861460-5257-466e-b2c1-4b8abcf86bd1
< 1.21.0
MEDIUM 6.4 The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜title’ parameter in all v… wordfence
847a4fc7-3580-421e-8045-41b5a85f2d97
< 6.1.20
MEDIUM 6.4 The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Sto… wordfence
8479d002-f2c1-4456-a653-2469c6705718
< 1.4.4.3
MEDIUM 6.4 The Xpro Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in versi… wordfence
84739305-2f10-4688-b038-c132e06da059
< 3.2
MEDIUM 6.4 The Image Wall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1 d… wordfence
8472cdbe-89a8-49ac-ab7e-065ebf717692
< 2.8.12
MEDIUM 6.4 The Yellow Yard Searchbar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yy_filter a… wordfence
846ccac2-ad56-4128-836d-2807c700c3fc MEDIUM 6.4 The HTML Tag Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in… wordfence
845cea77-ea74-4459-817b-cfbdb877b75a
< 6.0.4
MEDIUM 6.4 The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'osm_map' s… wordfence
8444743c-ba57-4a51-990c-eb9058829d09 MEDIUM 6.4 The Simple Wp colorfull Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' para… wordfence
8442fc5c-c940-4dc2-88df-676248fbc00b MEDIUM 6.4 The SvegliaT Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
← Prev 610 611 612 613 614 615 616 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top