πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 633 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
73524687-7703-4912-aad5-2a31122ba9b2
< 1.19.1
MEDIUM 6.4 The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPre… wordfence
73500260-4eff-4e56-a27c-1ff90b23e8d3
< 1.16.1
MEDIUM 6.4 The Interactive Content – H5P plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
733f5ded-e8cb-4895-b938-889cea32f027
< 1.1.38
MEDIUM 6.4 The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin f… wordfence
7329241f-f9a1-4afb-8030-e0bfe0dce283 MEDIUM 6.4 The scrollup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1 due… wordfence
73241750-cd21-4eee-9d43-8c5e26f9b9cf
< 5.8.1.2
MEDIUM 6.4 The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Go… wordfence
731a42fa-d48c-475e-8868-0ff5603b65de
< 2.1.7
MEDIUM 6.4 The User Login History plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
731089f1-ad98-4d6a-a165-f3d5970915a9 MEDIUM 6.4 The Geoportail Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
72fcb66d-ad00-4df0-a176-7b7c17756f52
< 5.8.6
MEDIUM 6.4 The Sahifa theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.8.6 due to insufficient … wordfence
72f1ffe1-d8af-4aa2-bc58-5f1cd4eaa856
< 1.22.0
MEDIUM 6.4 The Happyforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜className’ and 'anchor' bl… wordfence
72e1482c-0f55-4f43-8590-d4f2758f0eea MEDIUM 6.4 The Infogram plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.1 d… wordfence
72daa533-8b17-420c-9b51-b5f72da2726c
< 1.6.2
MEDIUM 6.4 The Widget Responsive for Youtube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube' shortc… wordfence
72c85bbd-2953-4f25-9a26-7edd48a4e50c MEDIUM 6.4 The Posts Slider Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
72c5d1b1-00bf-4352-b885-a8a7875c2bc6
< 8.15
MEDIUM 6.4 The MonsterInsights Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in ve… wordfence
72c2a5d4-f201-4cc8-ac49-cde1160ca468
< 1.3.3
MEDIUM 6.4 The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
72c0fc66-44c7-4657-878a-e5109178e8e3
< 3.4.1
MEDIUM 6.4 The Visual Composer Starter theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
72b76475-5215-47fd-badf-e2c542b25d4b
< 1.16.16
MEDIUM 6.4 The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Stor… wordfence
72b50c83-7128-4e38-9a5e-0954928ff002
< 2.0.17
MEDIUM 6.4 The jAlbum Bridge plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜ar’ parameter in all ve… wordfence
72aa9128-eecb-4090-ab9e-e5fbbfc1fb5c
< 6.1.1
MEDIUM 6.4 The WPQA - Builder forms Addon For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via slide… wordfence
72a74483-e159-4c51-a9e0-4a128cbf72dd
< 2.13.1
MEDIUM 6.4 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜… wordfence
72a6b040-ed02-4561-82f2-4adb820bdf7d
< 3.15.3
MEDIUM 6.4 The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in … wordfence
72a2449c-4292-45e6-bfe8-106f8043fcad MEDIUM 6.4 The vSlider Multi Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortc… wordfence
72a06690-f40a-472b-b9d1-985a49b914b3
< 1.2.0.1
MEDIUM 6.4 The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
729492e8-5625-444f-84ed-36b72cebc722 MEDIUM 6.4 The Arena.IM – Live Blogging for real-time events plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… wordfence
72876300-c9e0-41f1-bef5-f56e10b51e88
< 0.9.5.10
MEDIUM 6.4 The WPCal.io plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.9.5.9… wordfence
72779dd2-04eb-445d-88a0-28a9c4d2369b
< 7.1.0.31
MEDIUM 6.4 The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to… wordfence
← Prev 630 631 632 633 634 635 636 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top