πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 617 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
814f46c2-ac89-4743-81da-3b81a7853afc
< 5.8
MEDIUM 6.4 The Menubar WordPress plugin before 5.8 does not sanitise and escape the command parameter before outputting it back in … wordfence
814cce39-ef25-4d0f-b793-dca5c873f468
< 1.40.5
MEDIUM 6.4 The Gutenberg Block Editor Toolkit – EditorsKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
814488b9-2e0a-42f9-bfba-b4d249161099
< 1.2.7
MEDIUM 6.4 The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'serious-slider' s… wordfence
812cc8f1-f89e-47c4-b029-f6a3dbc55d70
< 2.4.29
MEDIUM 6.4 The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets … wordfence
8123fc2e-54c9-4e0d-b1c6-6f994f07e7e3
< 3.0.5
MEDIUM 6.4 The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPres… wordfence
810faad2-b63d-497c-af00-b57a07705608
< 1.2.0
MEDIUM 6.4 The Simple Iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attributes in versions up … wordfence
81022d05-d1fc-4f27-9f89-b6f9c79cc084
< 3.5.2
MEDIUM 6.4 Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary… wordfence
80f32108-16a5-478f-9966-7153735cad6d
< 3.1.46
MEDIUM 6.4 The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
80e0db86-0073-4797-93b1-aa2141f3e60a
< 3.0.7
MEDIUM 6.4 The Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor plugin for WordPress is vulnerable to Stored Cross-S… wordfence
80dc998d-24a6-4694-955c-63c62ace69be MEDIUM 6.4 The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
80ce6564-8559-4e99-a69e-d210db5c87f3
< 1.2.0
MEDIUM 6.4 The Button Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1… wordfence
80c700fa-619f-4ffe-a09a-bcdae2f71a7d MEDIUM 6.4 The SortTable Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the sortt… wordfence
80bd4b15-c2a8-401e-8901-fd008cb52f62
< 1.3.3
MEDIUM 6.4 The Solace Extra plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,… wordfence
80b71264-5b0f-41cb-86c1-a052d1976597
< 2.2.0
MEDIUM 6.4 The ONLYOFFICE Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'onlyoffice' shor… wordfence
80b1d728-b5aa-4811-b92a-9ce36abc2b80
< 2.0.8
MEDIUM 6.4 The Cognito Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versio… wordfence
809cd97c-22ea-49e7-be46-688fefe50236
< 4.4.2
MEDIUM 6.4 The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
8099c650-96d7-47b6-a81b-83ff663edb6b
< 3.5.0
MEDIUM 6.4 The Magic the Gathering Card Tooltips plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
8094e72e-1a9d-40da-95fb-14e341ce9ac1 MEDIUM 6.4 The TheGem theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.11.1 due… wordfence
808f5ddc-9ddb-456a-a497-deffac0744ba
< 1.9.4.1
MEDIUM 6.4 The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
808ef87d-298c-4622-9fcd-cf879e7157bd
< 2024.3
MEDIUM 6.4 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
808daff1-e9a8-45ee-adca-19b3391c1522 MEDIUM 6.4 The MasterBip para Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
808ba7c9-438f-4282-9b37-d56e079b6c2e
< 1.2.1
MEDIUM 6.4 The Plethora Plugins Tabs + Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
808695a2-4d34-4b43-88a6-7da788100f2e
< 1.0.11
MEDIUM 6.4 The HLS Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hls_player' shortcode… wordfence
807eadff-b39e-4d7a-9b0a-06fc18a90626
< 1.15.4
MEDIUM 6.4 The 3D FlipBook – PDF Flipbook WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu… wordfence
80635f61-a9b5-4536-b6ed-826c538fc16d MEDIUM 6.4 The News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 … wordfence
← Prev 614 615 616 617 618 619 620 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top