πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 629 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7700f1f3-90e2-450d-9cfe-c922d0cc6a1e
< 4.2.13
MEDIUM 6.4 The Slope Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slope-reservations… wordfence
76f7ca62-50b0-4d67-a6f6-7e79cadafc3f MEDIUM 6.4 The YouTube Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.… wordfence
76e46759-ff83-4a6b-b510-28965c88bb94
< 1.2.29
MEDIUM 6.4 The woo-variation-gallery plugin before 1.1.29 for WordPress has XSS. wordfence
76e35dc6-a4d2-4dca-a186-395f0dd954aa
< 1.0.0
MEDIUM 6.4 The ActivityPub plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user metadata in versions up to, a… wordfence
76d7588e-7062-419a-b0a2-ddc1955a710c
< 2.3.0
MEDIUM 6.4 The Counter Up – Animated Number Counter & Milestone Showcase plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
76cfe806-a8d9-4249-b2d0-eb3a314ca69a
< 3.1.1
MEDIUM 6.4 The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Fun … wordfence
76ccc688-79c0-4b6e-aac9-cf18baf9af46
< 1.52
MEDIUM 6.4 The Wufoo Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via numerous shortcode attributes … wordfence
76c8ffac-6971-4161-bd83-f53f6c6158db
< 1.8.0
MEDIUM 6.4 The WP Event Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
76c292dc-e9da-4256-82df-58ac5def4771
< 6.0.4
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for … wordfence
76ba273d-0919-45b3-8044-b8f0ff3972ab
< 1.7.15.1
MEDIUM 6.4 The Cooked plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.14 du… wordfence
76b987f1-2524-498a-a02c-a3ca390026e1
< 2.6.9.5
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Countdow… wordfence
76a4dbcd-b3f3-48e9-8175-c701837ac2ae
< 0.9.9
MEDIUM 6.4 The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.9.8 due … wordfence
769bc1fa-4f41-431e-9907-6e03d2c921be
< 1.56.1
MEDIUM 6.4 The SeatReg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'seatreg' shortcode in al… wordfence
769b9846-8c1d-4b7f-8bbe-d6665407cedb
< 4.3
MEDIUM 6.4 The Combo Offers WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
768d0ef5-5213-4283-b95e-ddfe0d2196bf
< 7.4.8
MEDIUM 6.4 The Zigaform – Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'z… wordfence
7683e708-b7cb-444e-9069-f33e4ef3ac76
< 2.2.2
MEDIUM 6.4 The Ocean Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via social icon titles in all… wordfence
7683a91d-8c16-481e-a300-590ac378890a
< 3.13.2
MEDIUM 6.4 The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the titl… wordfence
766cb6d0-1839-4d8c-819c-4e5dab408f6c
< 2.17.3
MEDIUM 6.4 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
766b5c62-0701-47d5-9839-445c2654d3e0
< 1.7.0
MEDIUM 6.4 The WP Accessibility plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
766ac399-7280-4186-8972-94da813da85e MEDIUM 6.4 The Newsletter2Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜style’ parameter in all… wordfence
76346f96-d2cd-44de-beb0-c15536a7305c
< 4.0.4
MEDIUM 6.4 The Copy Anything to Clipboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
7633efe4-f914-4683-a79b-baaa60975282
< 1.5.9
MEDIUM 6.4 A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.… wordfence
761a4801-fc4a-40a0-b5aa-303d88a87062
< 1.5.6
MEDIUM 6.4 The User Registration plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.5.5… wordfence
7614fa27-a5f3-4744-8b1e-716854fe7dac
< 2.7.8
MEDIUM 6.4 The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
75fe1d0c-52a3-4fcc-a80b-d05af7f2b0bc MEDIUM 6.4 The Smart Countdown FX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
← Prev 626 627 628 629 630 631 632 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top