🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 631 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
755a2c02-f442-46ca-9b45-644b7098b1e3
< 1.1.33
MEDIUM 6.4 The Heateor Social Login WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up … wordfence
755768e6-2260-4932-acde-54b246ccda07 MEDIUM 6.4 The Social button plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
755454cc-b1a8-4a38-9e73-c47a6ef562a2
< 7.13.54
MEDIUM 6.4 The Super Socializer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins [TheChamp-Counter… wordfence
7533b65e-3612-4c8e-8b67-3cbcb80b4331
< 1.1.21
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in the Lazyest Gallery plugin before 1.1.21 for WordPress allows remote attacke… wordfence
75154d59-458f-4a82-bff6-d28c1dbd8d7e MEDIUM 6.4 The WS Theme Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ws_weather shortc… wordfence
750be90d-dc12-4974-8921-75259d56c7b3 MEDIUM 6.4 The Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the nd_cc_meta_box_cc_price_ic… wordfence
75078a4d-8dc3-4b88-b1ec-f98ba0c01fac
< 5.10.5.2
MEDIUM 6.4 The TheGem Theme Elements (for Elementor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
75000e67-7914-43af-be1d-82990ada5129
< 3.11.0
MEDIUM 6.4 The Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'groups_group_info' shortc… wordfence
74ff6acc-b362-428a-b227-24282e0f2783 MEDIUM 6.4 The Dhivehi Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dhivehi' shortcode … wordfence
74f59ee0-19dd-4cc9-ab24-22f26d71d248
< 1.10.10
MEDIUM 6.4 The LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor plugin for WordPress is vulnerable to Stored C… wordfence
74e790e7-60fd-45cd-942f-0f24365d7fc8 MEDIUM 6.4 The Reviews Sorted plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'space' parameter of the [r… wordfence
74da323b-634b-40d0-b29c-901401cf6852 MEDIUM 6.4 The Parallaxer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.00 … wordfence
74cd34be-008c-4ff3-ae3c-417cfd2fee9b
< 3.3.62
MEDIUM 6.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after… wordfence
74bbe655-ce86-4a87-a79f-f25bd0680e49
< 1.12
MEDIUM 6.4 The Selection Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the search title field in versi… wordfence
74b27798-3c6f-4c4e-80f8-7aa40f704fb7
< 6.1.10
MEDIUM 6.4 The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Store… wordfence
74a7db23-f91c-452b-bc24-58fda69caf17
< 5.0.2
MEDIUM 6.4 The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[wp_ulike_likers_box]` shortcode… wordfence
74a23c66-3b72-4eab-9e65-c1b9c601f906
< 3.11.9
MEDIUM 6.4 The ThirstyAffiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
749c5d09-1e9a-4aa1-b7c2-6f9d24f3a09b
< 9.1.1
MEDIUM 6.4 The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Notes in all versions u… wordfence
7492cffe-6e17-4c59-8979-2fa168b4f41d MEDIUM 6.4 The Cryptocurrency All-in-One plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
748bc714-25ba-404e-ac3d-e588fd95b2f9
< 1.3.5.2
MEDIUM 6.4 The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
7486289b-3cb7-4f8b-abcb-9bfb4b82a95b
< 5.25.08
MEDIUM 6.4 The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in v… wordfence
7483762c-5356-4844-90a9-511d9ec48625
< 3.9.14
MEDIUM 6.4 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
746385e0-6bb9-47f2-a3e7-72f8e28be731
< 1.3.5
MEDIUM 6.4 The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Membe… wordfence
745dcc4c-1c52-4ac7-9ac6-033770282a3b MEDIUM 6.4 The Alpha Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alpha_block_css’ paramet… wordfence
745da770-dd78-4ffb-ae15-4b90682911e3
< 2.9.1
MEDIUM 6.4 The Yoga Schedule Momoyoga plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'momoyoga-… wordfence
← Prev 628 629 630 631 632 633 634 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top