πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 632 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
745709f4-bb9c-41c4-ab60-d9fc18e406a8
< 5.3.9
MEDIUM 6.4 The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
74551e01-063c-4493-8472-9c0903ac17c5
< 5.0.0
MEDIUM 6.4 The Daisycon prijsvergelijkers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'daisy… wordfence
745262f6-4f73-453e-b650-15115536f221
< 11.9.11
MEDIUM 6.4 The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the… wordfence
7447fc39-a517-4ba0-93d6-381a6eeb5b7b
< 2.1.10
MEDIUM 6.4 The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_heig… wordfence
7446bf86-81fa-4f89-8773-44b993ae2f7c
< 8.8.02.003
MEDIUM 6.4 The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
744310b2-ebe9-4dd5-8f18-6ba72c52dd61
< 2.1.8
MEDIUM 6.4 The WP Matterport Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode… wordfence
743de308-1152-40ad-8c77-bb9e222b9654
< 6.0.0
MEDIUM 6.4 The Advanced Custom Fields: Font Awesome Field plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers… wordfence
743a52f4-8412-4fc6-a1f2-e21711394b75
< 3.6.5
MEDIUM 6.4 The Simple JWT Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
7431ee0f-f485-48a4-9cdd-8fb2ac43e216
< 6.2.7
MEDIUM 6.4 The Weaver Xtreme Theme Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '[you… wordfence
741c479a-520b-46d7-b145-ffa8e6382788
< 5.0.3.1
MEDIUM 6.4 The Responsive theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 5.0.3.1 (exclusive… wordfence
7416f5e2-5c59-4192-a87c-b3174fd84a01 MEDIUM 6.4 The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' parameter in t… wordfence
74042b84-eee4-474e-afde-b101ad5ce467
< 2.2.0.3
MEDIUM 6.4 The JetProductGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
73e4ec2f-f4e1-469d-a4b7-5a10d44b7a2f
< 3.10.5
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title HTML… wordfence
73ddf729-da69-4d0b-866f-34a92ec72800 MEDIUM 6.4 The Video Onclick plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `youtube` shortcode… wordfence
73d89f61-e34a-493b-a856-63f1553f3000 MEDIUM 6.4 The Child Theme Generator WordPress plugin through 2.2.7 does not sanitise escape the parade parameter before outputting… wordfence
73d6efc5-8f91-453a-8c84-4b373aaf4d7a
< 1.2.4
MEDIUM 6.4 The Product Table For WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
73ca6a08-b01f-4df6-89ab-32b917c92236
< 1.4.2
MEDIUM 6.4 The RomethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, … wordfence
73c01967-262c-48ab-a464-401b1cadd4be MEDIUM 6.4 The BMLT Meeting Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_meeting_ma… wordfence
73aebd68-4f36-4999-844c-f09b10462ef8
< 1.0.9
MEDIUM 6.4 The GamiPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions … wordfence
73a82b69-0bd2-4b47-b27f-067875071cb8
< 1.3.2
MEDIUM 6.4 The Twice Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
73a25208-81fe-4337-a344-1c129bd80862 MEDIUM 6.4 The Mynx Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all vers… wordfence
7397898c-8d43-4399-9c2b-22f9287aa12d
< 6.4.2
MEDIUM 6.4 The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
737cc158-a18e-43ff-82c6-b33d090dc80b MEDIUM 6.4 The include-file plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1 d… wordfence
73615729-c32a-45f7-b2d8-5c978370e18c
< 1.9
MEDIUM 6.4 The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all v… wordfence
7352ab6d-b582-4512-a9fa-4b42b78fa862
< 1.4.0
MEDIUM 6.4 The Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all v… wordfence
← Prev 629 630 631 632 633 634 635 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top