πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 618 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
805d70d8-084b-4849-bf3e-c9cc7ec02bc5
< 1.9.7
MEDIUM 6.4 The GS Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters such … wordfence
8056af63-e81f-4321-991e-d201ad1095c4
< 1.9.1
MEDIUM 6.4 The Gutenverse – Gutenberg Blocks – Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cross-… wordfence
8053e812-21c0-4e3a-8d5b-52ef9991eb61
< 1.3.21
MEDIUM 6.4 The Judge.me Product Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p… wordfence
804a973e-4650-428c-910f-09e4fc3aa4bb
< 4.3.0
MEDIUM 6.4 The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to … wordfence
802cd945-043d-4cbe-8dbc-474846fb62af MEDIUM 6.4 The Generic Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
802c9177-becf-4c54-ada9-a6de8904a322
< 2.0.0
MEDIUM 6.4 The Cal.com plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.0 du… wordfence
8023be86-2bdb-4f16-9b54-a959f1e75e46
< 2.7.0
MEDIUM 6.4 The Responsive Flickr Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fsho… wordfence
80235228-f23c-4f8e-9d26-b66cd44c4bed MEDIUM 6.4 The Hola Free Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
801a48ab-f4b7-4194-a9ee-719c74e36ea2
< 1.9.1
MEDIUM 6.4 The utm.codes plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.… wordfence
800eba54-1bfb-4f44-9d5f-ca650e7fea30
< 1.8.0
MEDIUM 6.4 The Cooked Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.8.0 due to insuffic… wordfence
800c55b1-7d1f-4525-a4c3-8da5b69355fb MEDIUM 6.4 The SetMore Theme – Custom Post Types plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
7ffcb74b-230b-4629-b22d-5db96ac5fa06
< 1.1.11
MEDIUM 6.4 The Your Friendly Drag and Drop Page Builder β€” Make Builder plugin for WordPress is vulnerable to Server-Side Request … wordfence
7fe5cc35-8f76-43e3-8fbd-c5a2bda165e1 MEDIUM 6.4 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting in v… wordfence
7fe5240f-f6c3-43f2-b17c-e7d94905ea79
< 2.2.6
MEDIUM 6.4 The Easy Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
7fe140ea-9d29-49be-a425-ada274290932 MEDIUM 6.4 The Tito plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3 due to … wordfence
7fdd1b1c-84b5-451a-a921-80be3b154398
< 2.1.5
MEDIUM 6.4 The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'course_carouse… wordfence
7fdc9003-35e9-4fe9-a3e9-353d6bab525a
< 1.3.7
MEDIUM 6.4 The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid p… wordfence
7fdad62e-d43a-4eb8-a637-0a257f3f18d4
< 5.8.12
MEDIUM 6.4 The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'… wordfence
7fd5d31d-a4f3-458a-b457-f20aeaa71749
< 4.8.2
MEDIUM 6.4 The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable t… wordfence
7fd2e4ab-61a2-4a92-b11e-746ef64f2f2a
< 2.7.9.9
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
7fc20069-5c1d-481a-b0fd-6f29ed6b41ee MEDIUM 6.4 The Grid Accordion Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'grid_accordi… wordfence
7fbd3170-a45b-4ae6-bc59-4cfb92f6c2a6
< 5.10.30
MEDIUM 6.4 The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is… wordfence
7fbb7a39-936b-48f1-97f1-46dc23180b00
< 1.9.0
MEDIUM 6.4 The Mongoose Page Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes i… wordfence
7fb4f15f-a432-413f-b6b8-7480559e10f3 MEDIUM 6.4 The Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.58 … wordfence
7fab0e10-d388-41d4-a01f-9bbb8c3cfb5f MEDIUM 6.4 The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in … wordfence
← Prev 615 616 617 618 619 620 621 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top