🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 615 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
83695ac4-a08b-4c25-ac33-d9b7498f5a2c
< 4.23
MEDIUM 6.4 The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-no_number’ paramet… wordfence
8368e18a-14b8-452f-aad8-0d550302a4a4 MEDIUM 6.4 The Mage Front End Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
83660c88-1115-450d-88b0-29d62319dac7 MEDIUM 6.4 The Advanced post slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
83603d33-b616-4332-aa05-b8ac61424614 MEDIUM 6.4 The InventoryPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the description parameter in ve… wordfence
835aaf5e-08c8-4bf8-add7-82a1f1fdc2c0
< 2.2.2
MEDIUM 6.4 The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
8352400f-fea1-486d-872a-66340300cee9
< 1.2.55
MEDIUM 6.4 The Magical Posts Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mpac_title_tag' par… wordfence
834c92ba-8b48-4ae3-9073-085e8f559762
< 4.1.38
MEDIUM 6.4 WordPress Core failed to sufficiently sanitize block attributes in versions up to, and including, 6.2. This makes it pos… wordfence
8331fe3f-e943-4f4c-887f-761f3e18eb79
< 1.2.3
MEDIUM 6.4 The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
831d9e4d-21b4-45db-83f8-e8b220c6c44b MEDIUM 6.4 The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
831d5b15-513b-45bd-b049-c83d92e731ec MEDIUM 6.4 The Zoho Creator Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
830ac75b-708a-435c-8837-b79a2f41575c
< 3.5.3
MEDIUM 6.4 The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twit… wordfence
83082d5f-b65b-47cb-9026-8b23800c0e28 MEDIUM 6.4 The Slicko plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.0 due… wordfence
82fb39e0-8f49-4274-87de-a191b43657a0
< 3.14.2
MEDIUM 6.4 The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
82ec3600-1e32-4871-a41f-ab42d7bded5d MEDIUM 6.4 The Narrative Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
82e5fd9f-9a1f-4a4c-ac06-61bf65e3c8ab
< 2.9.13
MEDIUM 6.4 The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Mouse Cursor mod… wordfence
82e2d184-d922-4ddb-b3aa-0191f7ff7603 MEDIUM 6.4 The Author Bio Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
82c9a361-8a69-4468-8f3e-3caa2c169332
< 1.3.7
MEDIUM 6.4 The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
82c788eb-373b-47be-abe6-f4cef3291b10
< 2.0.8.1
MEDIUM 6.4 The BNE Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
82c08769-2bb6-4c87-b198-f18216b3e744
< 2.0.6.1
MEDIUM 6.4 The Library Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting the plugin's shortcode(s) in versio… wordfence
82b5ade8-582e-4440-b043-d30e757c9467
< 1.6.2
MEDIUM 6.4 The MediaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mpp-uploader shortcode… wordfence
82892be3-91d5-4350-96b0-dc68a67b4637 MEDIUM 6.4 Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled prettyPhoto librar… wordfence
827c0459-1328-4fb1-b044-ae80298fa5ea
< 1.2.2
MEDIUM 6.4 The Coupon Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Coupon Code' parameter in a… wordfence
826e7e0a-79b1-4828-8eeb-159ef3cc2c65
< 6.2.3.0
MEDIUM 6.4 The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable t… wordfence
826b5dac-4a54-44c7-979b-8901bb468777
< 5.0.0
MEDIUM 6.4 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
826a2003-c526-4760-8c21-10d5ae7bb384
< 4.0.5
MEDIUM 6.4 The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _elementor_data … wordfence
← Prev 612 613 614 615 616 617 618 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top