🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 630 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
75fa3541-6410-4e3e-9f17-c39b7321c5ec
< 1.2.4
MEDIUM 6.4 The Easy Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.… wordfence
75e55138-b091-4113-89da-e1ca45fb99ea MEDIUM 6.4 The Google Doc Embedder plugin for WordPress is vulnerable to Server Side Request Forgery via the 'gview' shortcode in v… wordfence
75e41e78-ce8c-4248-9eca-b36391fbbbde MEDIUM 6.4 The WP Applink plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all ve… wordfence
75dafb36-7596-492f-a377-32315b1abe33
< 2.3.0
MEDIUM 6.4 The BuddyMeet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions u… wordfence
75da181d-3162-448f-afb8-dc05748184f6
< 2.6.9
MEDIUM 6.4 The Exclusive Addons Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
75cf7c78-ffce-4f30-a542-efd86b8542cc
< 2.1.9
MEDIUM 6.4 The Nova Blocks by Pixelgrade plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
75cc74f6-aaab-4d5a-bd71-c238fa74a9bb
< 1.3.17
MEDIUM 6.4 The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new cal… wordfence
75c5602c-1369-43e4-8010-4a3dfa9bef1f
< 1.5.9
MEDIUM 6.4 The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
75b09cf8-cfe4-4a8a-838c-e4b1cedf5d5a
< 1.1.42
MEDIUM 6.4 The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
75ad72b7-c1ac-4f91-8a55-bfee456bec15 MEDIUM 6.4 The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
75a3a8ee-42c6-4963-bb48-6794b310b861
< 1.1.6
MEDIUM 6.4 The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Actio… wordfence
75a1f49d-2352-40f0-a830-7cff0e5163f2
< 5.1.11
MEDIUM 6.4 The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via pricing table options… wordfence
75993820-e3bb-43c4-92a6-5aad2a7187e9
< 1.0.10
MEDIUM 6.4 The Review & testimonial widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
7595a1f6-6923-4102-8efe-a414adebce65
< 2.4.7
MEDIUM 6.4 The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ocean_gallery_id’ parameter… wordfence
7593b8b5-36c0-4c68-b1f2-d505fafc3328
< 1.0.20
MEDIUM 6.4 The Fleetwire Fleet Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fleetw… wordfence
75938876-d644-47b1-a0b9-c3544f23186d
< 2.3.5
MEDIUM 6.4 The Listamester plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.… wordfence
758e23b9-c3d5-4f1c-9659-66483d6f0578
< 1.1.30
MEDIUM 6.4 The Magical Products Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mpdpr_title_tag'… wordfence
758beea4-809c-4837-839d-76ee982d0ae5 MEDIUM 6.4 The Knight Lab Timeline plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inc… wordfence
757e7eec-ac03-4d5b-8307-b167f9b3d5b5
< 1.2.9
MEDIUM 6.4 The Free WooCommerce Theme 99fy Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
757d8211-88d5-4187-9f82-79339ed70825
< 2.9.12
MEDIUM 6.4 The ListingPro - WordPress Directory & Listing Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
757b776b-d0b1-46ee-a58f-48979c3c1b2e MEDIUM 6.4 The Mixcloud Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
7575e290-ad31-4c1b-9a89-eaa8b3eda6d1
< 2.1.8
MEDIUM 6.4 The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via one or more shortcodes incl… wordfence
75642531-781a-4c5b-84ae-0e25669d7e40
< 3.1.7
MEDIUM 6.4 The Real Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
755e0998-0f0d-4259-881d-ed07aecb0b10
< 1.0.16
MEDIUM 6.4 The Themedy Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themedy_col, them… wordfence
755ae574-9df3-44d1-a14b-16887f234510
< 1.0
MEDIUM 6.4 The Scheduled Announcements Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height_set… wordfence
← Prev 627 628 629 630 631 632 633 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top