πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 635 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
717dfceb-dc0b-45ef-bc06-72658486d1f1
< 1.1.6
MEDIUM 6.4 The Simple Testimonials Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to… wordfence
71738a18-84ac-4cd9-bf1f-870813afc12d
< 1.6.6
MEDIUM 6.4 The HT Slider For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
71597452-ac9a-4f1f-8b3a-3b711e2fcb38
< 2.1.6
MEDIUM 6.4 The PropertyHive plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1… wordfence
71564eec-426a-46fa-b614-388bebae6ebd
< 7.1.2
MEDIUM 6.4 The WP Shortcodes Plugin β€” Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
7152253a-7bb8-4b5c-bffd-86e46df54b7e MEDIUM 6.4 The WDContactFormBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Contact_Form_Builder… wordfence
7150179c-e449-4574-a9d3-bd4acf43b3c1 MEDIUM 6.4 The RJ Quickcharts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin… wordfence
7147cb69-294e-4270-bf8b-3a32a5552d1e MEDIUM 6.4 The MM-email2image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in al… wordfence
71408e0b-aed8-4077-add2-7f3b249e85f5
< 5.3
MEDIUM 6.4 The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
713f5bf5-f282-436e-8e8c-18543458bea1 MEDIUM 6.4 The WordPress SEO Friendly Accordion FAQ with AI assisted content generation plugin for WordPress is vulnerable to Store… wordfence
713b4fbc-7a46-40b1-8c4e-088a9859d7da MEDIUM 6.4 The Modernize theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.0 d… wordfence
71378c94-c2e6-43a9-bb8b-f2ffb153f3fe
< 6.1.10
MEDIUM 6.4 The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
7134bb24-11a1-41f9-ad34-b4527c22463c
< 1.2.7
MEDIUM 6.4 The Card Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Profi… wordfence
7129e5cb-ce70-477a-a8f1-3acf152dfc21
< 2.9.85
MEDIUM 6.4 The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin… wordfence
71167dec-38ec-4eb3-8fab-25eca0f8b071 MEDIUM 6.4 The BitForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bitform' shortcode in ve… wordfence
70eaf9b8-67a0-4e98-b65c-aea61b20b448 MEDIUM 6.4 The Freemind Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'freemind' shortc… wordfence
70e6c4cd-c415-4f17-8bc4-353aa04dda9a
< 1.3.19.1
MEDIUM 6.4 The JetBlocks For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
70c41a28-982f-43e6-9415-3a2d996959f3
< 1.1.1
MEDIUM 6.4 The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'smartdocs_search' sho… wordfence
70beb971-9863-46c1-888a-fd8e02a9b18b
< 1.1.27
MEDIUM 6.4 The CubeWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.26 du… wordfence
70bda4b7-e442-4956-b3cb-8df96043bcde
< 8.3.3
MEDIUM 6.4 The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom class … wordfence
7092f2c4-1f50-4daf-a428-cc80a0aaa77c
< 2.1.6
MEDIUM 6.4 The Author Box WP Lens plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
70682a2d-16f6-4d7e-bf69-f0f3999f03de
< 1.5.4
MEDIUM 6.4 The Salient Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'icon' shortco… wordfence
706549d9-aa2f-4b1e-83b8-0eea38654565 MEDIUM 6.4 The Print-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
705f5adc-4be5-49bf-8244-f8b459d99c69 MEDIUM 6.4 The LIQUID SPEECH BALLOON plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
705b1da0-df92-40c2-a608-ccad32a9c224 MEDIUM 6.4 The SP Blog Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'design' attribute of the… wordfence
705a0e1f-79c6-4c2a-8622-fb3df944cf22
< 3.7.5
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and … wordfence
← Prev 632 633 634 635 636 637 638 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top