πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 628 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
778e2191-d764-44a1-9f52-9698e9183fd2 MEDIUM 6.4 The SlideOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versi… wordfence
778d8443-fc0f-4e97-8460-e5ceee8b62a1
< 3.9.15
MEDIUM 6.4 The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gu… wordfence
778af777-4c98-45cd-9704-1bdc96054aa7
< 1.3.1
MEDIUM 6.4 The Poptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'poptin-form' shortcode in versions up … wordfence
777eb35b-c829-4a3b-a9e9-6d766f062813 MEDIUM 6.4 The Text Advertisements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
7774cdfd-622a-4608-9efd-273923a0d0aa MEDIUM 6.4 The Local Syndication plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu… wordfence
7773fd3a-2417-415e-97b0-735e99e62097
< 1.6.46
MEDIUM 6.4 The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG… wordfence
7773650c-99dd-4492-b9d7-e931d178b31e
< 1.0.4
MEDIUM 6.4 The Plain Post theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.3 … wordfence
7772c78e-3134-4855-ac4e-3520c584c2e7
< 4.2.2
MEDIUM 6.4 The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to,… wordfence
77727d02-796b-4c5b-ad5d-d1c366760abc
< 7.9.9.2
MEDIUM 6.4 The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress i… wordfence
7770ab04-eb40-450e-ab8a-2a8e5d13d4a4
< 1.4.5
MEDIUM 6.4 The GS Insever Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s)… wordfence
775b6034-617a-4d84-a8fe-773ffbd9742a MEDIUM 6.4 The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tx_woo_wis… wordfence
7759d119-503f-4097-83ba-6c469276450d
< 1.6
MEDIUM 6.4 The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-S… wordfence
775891d7-d02e-4f6c-a16c-8441a4f1d2cd
< 2.7.34
MEDIUM 6.4 The FooBox Image Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
7749c45a-f956-4df6-98d0-5ec0db95185e
< 4.15
MEDIUM 6.4 The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'elevation-trac… wordfence
7745de26-8c38-48db-a361-a243519f0237 MEDIUM 6.4 The Inline Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
773b6c7e-f3ea-4827-93e3-b76b6adbac8f
< 3.12.8
MEDIUM 6.4 The YMC Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.12.… wordfence
772e843b-00ea-45f5-b730-c9a793d4c2db
< 6.6.15
MEDIUM 6.4 The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
77247a6b-2473-4b36-9ad8-b7802e4fad32
< 1.3.4
MEDIUM 6.4 The WP-WebAuthn plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wwa_login_form shortc… wordfence
771ecb8c-feb1-40ea-b47b-a2ae033b3c87 MEDIUM 6.4 The TM WooCommerce Compare & Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tm_woo_wish… wordfence
77137612-d36c-4c75-a9d3-469bf5faa6a1
< 3.8.3
MEDIUM 6.4 The Marquee Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
77122403-5865-40d7-96d5-557147098c4e MEDIUM 6.4 The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' parameter in t… wordfence
770dbc3c-d05c-453e-bf64-5d45f395c53b MEDIUM 6.4 The Magic Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
7709f5c9-a938-4e6e-8430-6468fb618ef3
< 2.9.1
MEDIUM 6.4 The IssueM plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.0 due… wordfence
77033d00-f794-4dbe-9454-17c312855491 MEDIUM 6.4 The A Simple Multilanguage Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'as… wordfence
7701f05b-3c74-4e0b-aa12-3a17f799ca67 MEDIUM 6.4 The CookieHint WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
← Prev 625 626 627 628 629 630 631 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top