🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 616 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
826483d7-948d-46c4-890c-71001b03847c
< 3.10.5
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image … wordfence
82644c46-205b-4005-bba8-6b3e45769639
< 1.6.25
MEDIUM 6.4 The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the flyout_l… wordfence
8260a74a-e338-42f6-ad9d-cb30f1a9bc86
< 1.7.6
MEDIUM 6.4 The Simple Post Notes plugin for WordPress is vulnerable to subscriber+ Stored Cross-Site Scripting via the 'spnote' par… wordfence
8256b8e4-f8c5-4feb-b6e4-668ed3b6fccd MEDIUM 6.4 The Boot Store theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the … wordfence
8247a05c-0a23-4f0c-8578-d679df773401 MEDIUM 6.4 The Postcasa Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
824360ab-c797-465a-8480-baeae941af29
< 12.8-a.3
MEDIUM 6.4 The Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attribute in versions up to, and… wordfence
823418d9-a231-4306-8575-2937a491509f
< 6.11.7
MEDIUM 6.4 The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user display name in all vers… wordfence
82253cd8-e9ff-4f3d-8844-c270dae445a4 MEDIUM 6.4 The MediaElement.js – HTML5 Video & Audio Player for WordPress is vulnerable to Stored Cross-Site Scripting via the pl… wordfence
8207ae15-b6ae-4b58-8877-1f87c12dbe7c MEDIUM 6.4 The WP SHAPES plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up … wordfence
82061b1f-a717-4007-978c-a3875669556f MEDIUM 6.4 The Sheets2Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titles' shortcode attribute … wordfence
81f61ef0-b3c7-4c69-bd18-5e5f0ea09abc
< 4.5.4
MEDIUM 6.4 The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to S… wordfence
81cb9888-2a1c-4cfd-ad62-ed8cfc2f22b3 MEDIUM 6.4 The Smooth Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
81c4dd54-a248-48a0-a407-ffd3162e0abe
< 1.3.0
MEDIUM 6.4 The Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in version… wordfence
81b9cebd-eff6-4650-977e-ee81089e683a MEDIUM 6.4 The Levo Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘image_description’ par… wordfence
81b079d7-937a-4a30-8e52-716989a37b77 MEDIUM 6.4 The Thumbnail Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
81a82caf-4013-42c4-ad63-4e13bfa4322f
< 1.0.215
MEDIUM 6.4 The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HowTo bloc… wordfence
81a48c61-4191-4252-9230-9df8fc5e3443
< 5.9.10
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
81998d01-8ae7-44ac-a22e-7bdbebee6c49
< 1.3.9
MEDIUM 6.4 The Easypromos Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Easypromos shor… wordfence
818de7f7-913a-4ade-927e-bba281b4709a MEDIUM 6.4 The iframe forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'iframe' shortcode in version… wordfence
8188c96d-6658-42da-bfea-10a7044348a0
< 1.0.7
MEDIUM 6.4 The Delisho plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.6 du… wordfence
81803a24-51ba-4d23-88ef-553cb4754977 MEDIUM 6.4 The CC-IMG-Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'img' shortcode … wordfence
8169e533-ef3b-4fd7-9571-61e5528b7652
< 4.1.3
MEDIUM 6.4 The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Stored Cross… wordfence
8159ee7c-69ac-4422-ba8b-664f1fee8e07 MEDIUM 6.4 The Product Slider For WooCommerce Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Meta Keys … wordfence
81559c61-8816-462d-a64d-6b039fd15b1d
< 1.0.03
MEDIUM 6.4 The Shortcode Redirect plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
81500371-93d3-4cee-a992-93d2469f5233 MEDIUM 6.4 The SimpleSchema plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7… wordfence
← Prev 613 614 615 616 617 618 619 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top