ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 634 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
72662a59-f41c-4df7-aa04-7243ff43c48d
< 1.3.2
MEDIUM 6.4 The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in … wordfence
725feb15-aa9b-4c00-bb95-ee0616000a14
< 1.2
MEDIUM 6.4 The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’… wordfence
7250aaa2-c778-4899-af76-6b3f79cff486 MEDIUM 6.4 The Client Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
7242d808-9c33-4b3f-bda6-b4b72ca37de9
< 5.9.12
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
723ed5c7-041f-4e03-83ad-43438e3265a1
< 3.6.0
MEDIUM 6.4 The Logo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via numerous shortcodes in versions up… wordfence
7234d4b9-a575-428a-9d08-2dc62ba41c30
< 4.1.2
MEDIUM 6.4 The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
722fa61c-4b88-41cc-bbf1-6ee3220b71a8 MEDIUM 6.4 The Jobs for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
722f7d6e-f082-428e-8d9e-a4d0f99bc7ec MEDIUM 6.4 The SKSDEV Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
722956ec-d2f5-42ad-bb95-776ad620d788
< 1.1.1
MEDIUM 6.4 The Grid Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
72131ba4-976b-4f89-9a69-2469f22eb5fd
< 7.7.7
MEDIUM 6.4 The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field… wordfence
72113d42-1a93-4979-849b-ba8038231417
< 1.1.0
MEDIUM 6.4 The Easy Call With Twilio plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions … wordfence
720a3525-01dd-4cfd-9403-2bc3f87df618
< 6.9.1
MEDIUM 6.4 The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for Word… wordfence
7205c238-4419-4292-8f9c-4ccf5b69dd60
< 2.0.79
MEDIUM 6.4 The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ez-toc` s… wordfence
71fd62e7-fa6a-49d7-9c5f-a54490b9cdd1
< 3.0.59
MEDIUM 6.4 The Search, Filters & Merchandising for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
71f78fef-50f6-49d5-94f6-6d0cf1b8f536
< 5.10.3
MEDIUM 6.4 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for… wordfence
71f74a54-2693-4dab-91a1-903a906cc0f1
< 5.5.9
MEDIUM 6.4 The Tooltipy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.6 d… wordfence
71eeddf4-5693-41bc-93ad-3c93dafdd3bc MEDIUM 6.4 The Webico Slider Flatsome Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wbc… wordfence
71df1c9a-b4fa-47c7-93c7-f2cb09fad3ab MEDIUM 6.4 The Donations plugin <= 1.8 for WordPress is vulnerable to Authenticated stored Cross-Site Scripting (XSS) by users with… wordfence
71da3176-ce22-4860-a036-77c56dc6507a
< 3.31.9
MEDIUM 6.4 The Leyka plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.31.8 due… wordfence
71d8a8cf-4653-4515-95ce-8d71697e189c
< 5.6.3
MEDIUM 6.4 The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordP… wordfence
71c17349-41d6-4c6f-b8ff-69ac818c2903
< 1.0.7
MEDIUM 6.4 The Fable Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.… wordfence
71a933ef-f49d-4520-90d5-9957f72d7452 MEDIUM 6.4 The WP YouTube Video Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ib_yo… wordfence
71a0aa95-f2a9-4537-a8d1-d78336e36125 MEDIUM 6.4 The Scheduling Plugin – Online Booking for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
718c60c1-6117-4959-a907-d0ef457f7185
< 6.0.0
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
717eba02-4ee0-4eb4-b1fb-0939e09d04c9 MEDIUM 6.4 The Compare Ninja plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
← Prev 631 632 633 634 635 636 637 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top