πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 636 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
70582781-9de5-4124-bde4-d3d26724e9b3
< 1.3.972
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
7054dda8-4be4-4680-8d14-20e52e225e63
< 4.3.0
MEDIUM 6.4 The Jobify - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
704a7df0-8e6b-4145-96a2-d179a6d75aac MEDIUM 6.4 The WE – Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Testimonial Author N… wordfence
704a26f1-36d9-4503-b200-5a6b604ceddc
< 2.0.74
MEDIUM 6.4 The Radio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0… wordfence
70254a2f-08da-4f78-85d1-08c746167e0f MEDIUM 6.4 The WP Best Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0… wordfence
701e349b-ce59-4724-8304-3871a3abbe8b MEDIUM 6.4 The zBench theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.2 due … wordfence
701dc461-88e7-40bf-a4fb-f92723b6e05e
< 1.5.2
MEDIUM 6.4 The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in… wordfence
701bcf98-fcb4-4722-9bf1-b94efe3bb1fd MEDIUM 6.4 The WordPress Menu Plugin β€” Superfly Responsive Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
700ef470-dfa9-498f-b4a4-57b85a349f35 MEDIUM 6.4 The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
700b9a34-bf9c-444d-80c7-87bf9412673f
< 1.9.15
MEDIUM 6.4 The Compact WP Audio Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and… wordfence
7008a8a9-dd6f-413b-b530-755528391bca MEDIUM 6.4 The Pootle Pagebuilder – WordPress Page builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in a… wordfence
700755ff-6619-499e-adda-5b1fc4466dbe MEDIUM 6.4 The Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.8.1 … wordfence
6ffb494a-e9b3-46f5-825a-35ad88d5d6fa MEDIUM 6.4 The Eleblog – Elementor Blog And Magazine Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
6ffa6a6b-bbb4-4361-8585-ce2cdb7d1d7e
< 2.9.13
MEDIUM 6.4 The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_fbchat_app_id'… wordfence
6fc2b2a5-00b0-424e-8678-c6b5cd76baec
< 2.0.25
MEDIUM 6.4 The Beds24 Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in … wordfence
6faf7e36-52d7-4578-bb71-2b64a761692b
< 8.5.3
MEDIUM 6.4 The Geo Controller plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin… wordfence
6fa49a4a-867c-42a0-8cf6-a28dd9691bb5
< 3.1.4
MEDIUM 6.4 The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin… wordfence
6f90c0d8-ede6-4f24-870f-19e888238e93 MEDIUM 6.4 The Display post meta, term meta, comment meta, and user meta plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
6f8570c5-1e4d-4df9-bd91-ccdf8e72afbc
< 45.15.0
MEDIUM 6.4 The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
6f849ec6-1c90-4f98-a367-fea87ddc5870 MEDIUM 6.4 The Formidable Kinetic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'kinetic_link' shortcod… wordfence
6f7c164f-2f78-4857-94b9-077c2dea13df
< 1.58.2
MEDIUM 6.4 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the code editor in a… wordfence
6f589b5d-9cdb-4521-bc60-c8f19d0ef982 MEDIUM 6.4 The Animated Headline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animated-headl… wordfence
6f54053e-30ff-449b-b696-92d503011a4d
< 3.13.1.3
MEDIUM 6.4 The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
6f524163-4d4c-40fc-b58a-311f1f6cac15
< 1.6.3
MEDIUM 6.4 The Educenter theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Circle Counter Block in all versi… wordfence
6f3fd683-9522-4e41-9ae7-751837c1844f
< 3.0
MEDIUM 6.4 The PDF Catalog Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
← Prev 633 634 635 636 637 638 639 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top