🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 614 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
84389347-5dc2-4c58-bc73-1d7384241c2c
< 3.1.4
MEDIUM 6.4 The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
8437abcc-3e34-4a8a-bfe2-2ff7c9f41164
< 6.7.8
MEDIUM 6.4 The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmltag’ parameter … wordfence
84262b4a-a662-4aaf-9eae-f5cca8f6cd06
< 1.6.7.18
MEDIUM 6.4 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to S… wordfence
841e999a-3501-4295-bfea-8027a5ed3308
< 3.8.1
MEDIUM 6.4 The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
841adf53-930a-4286-96d0-9ee8b0c188c4 MEDIUM 6.4 The LJUsers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'ljuser' s… wordfence
840fd950-3ce3-4068-b8bc-270f168a5091
< 1.2.8
MEDIUM 6.4 The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in th… wordfence
840dd4a9-103a-4ff9-ba26-3bf5b6e831a1
< 1.4.2
MEDIUM 6.4 The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘label_yea… wordfence
840b4382-8175-4811-995c-2828fabcd97c
< 1.0.24
MEDIUM 6.4 The Booking Calendar Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
8407b678-76c5-4232-b17e-8db05f9e7b12
< 1.7
MEDIUM 6.4 The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
83f7d9b9-793e-4380-b971-bc13c77a06a8
< 1.3.1
MEDIUM 6.4 The Slotti Ajanvaraus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slotti' shortc… wordfence
83f21ed2-305a-4c5c-a2d5-7ddc35a7459b
< 2.4
MEDIUM 6.4 The Dynamic User Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
83ea2ec3-5d5b-44ea-83e6-41c4fa6e2e5f
< 1.3.972
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
83e1f631-28ec-4924-9d69-caaba00fe276 MEDIUM 6.4 The real.Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1… wordfence
83d78ff7-bd59-431e-b579-156e23ede053
< 1.8.17
MEDIUM 6.4 The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up … wordfence
83d5337b-8c06-41ee-b18c-2c39150a7f30
< 2.5.5
MEDIUM 6.4 The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
83ac0dfc-88cd-48f0-9914-2258d5dfe834 MEDIUM 6.4 The Upfrontwp theme for WordPress is vulnerable to Stored Cross-Site Scripting via an unspecified shortcode or parameter… wordfence
83a81b1c-40cf-43ea-a36d-eaf342e65fc2
< 4.24.0.1.24.0
MEDIUM 6.4 The Sensei Pro (WC Paid Courses) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to… wordfence
83a0150d-a9fa-4cc2-8fe8-a429747a9964
< 1.3.981
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via… wordfence
839ecd06-9c74-4ddc-b455-26ec3e627889
< 6.1.1
MEDIUM 6.4 The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's osm_map and… wordfence
8397e583-a8f5-422c-805d-c43328c4bc84
< 3.21.4
MEDIUM 6.4 The Ultimate Addons for WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
8396c124-9c72-4801-8964-1cd5fbd52d20
< 2.3.21
MEDIUM 6.4 The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and inclu… wordfence
838bfa4c-2eb7-4f76-a6c3-ab4684f3913c MEDIUM 6.4 The Aggregator Advanced Settings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads … wordfence
8373938c-060a-4579-a133-d25b4d065d36 MEDIUM 6.4 The WooCommerce Cart Count Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's … wordfence
83734fe1-23e5-4b40-8daa-f5c8b9f9896a MEDIUM 6.4 The Legacy ePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0… wordfence
836a646c-af96-45eb-841d-c6bde270a27e MEDIUM 6.4 The WP-GraphViz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.… wordfence
← Prev 611 612 613 614 615 616 617 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top