πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 637 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6f3e4e53-3a4a-4b9d-845c-927a59e03488
< 1.4.2
MEDIUM 6.4 The HashBar – WordPress Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unkn… wordfence
6f3bcf70-2900-4a13-9ed4-264a15af9725 MEDIUM 6.4 The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parame… wordfence
6f2ef250-f951-4408-ac42-3272ddf46530 MEDIUM 6.4 The Canto Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fx' shortcode attribut… wordfence
6f2b4ac7-f888-408b-a77a-bd73ac8e967d
< 1.7.11
MEDIUM 6.4 The Drop Shadow Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in… wordfence
6f2b46a9-d228-43b4-84af-d56218076087
< 3.8.25
MEDIUM 6.4 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
6f05b58a-3cab-4069-ae9e-fec82bb5cd47 MEDIUM 6.4 The Naver Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions … wordfence
6ef9a757-625b-417a-b0ec-f13e2ff4f0f4
< 6.5
MEDIUM 6.4 The WP Visitor Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes … wordfence
6eedf009-116c-4a98-8b84-e01bd35e7e60
< 2.0.54
MEDIUM 6.4 The ultimate-member plugin before 2.0.54 for WordPress has XSS. wordfence
6eec349a-0b85-4d3f-bdb7-f9eb3b9e35d9 MEDIUM 6.4 The Image Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
6ed5bdb3-c4cd-4982-bc47-feeff527e284
< 3.1.14
MEDIUM 6.4 The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox i… wordfence
6ecf99ef-f879-426f-8a05-129be77f1157
< 1.6.6
MEDIUM 6.4 The Mihdan: Yandex Turbo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortco… wordfence
6ebb5654-ba3e-4f18-8720-a6595a771964
< 1.12.12
MEDIUM 6.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_to parameter… wordfence
6eba6056-e087-4347-ad36-96501ceb4cdd
< 3.14.4
MEDIUM 6.4 The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress i… wordfence
6eb8756b-7c0f-4bc9-9e24-07598efa9eee
< 28.1.4
MEDIUM 6.4 The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via an Elementor display setting in all ver… wordfence
6ea2b350-7def-4af0-b872-60f28fcdc3c8 MEDIUM 6.4 The Classy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
6e984ff1-9dcf-4cd3-b617-1f9e25ecae0c
< 1.0.19
MEDIUM 6.4 The WC Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.1… wordfence
6e8a3628-b7cf-4f1a-89dc-d7e58257b2e4
< 3.1.5
MEDIUM 6.4 The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcod… wordfence
6e83c039-9b15-4e0c-8b07-3b906938c138 MEDIUM 6.4 The Mstoic Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'start' parameter of the… wordfence
6e7dcd0e-fbc8-4460-82a2-4ed20664e2b6
< 1.8.2
MEDIUM 6.4 The Product Catalog Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
6e78440d-54ab-400f-a8d2-9cb33f1ec861
< 1.6.4
MEDIUM 6.4 The WordPress Portfolio Plugin – A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more plugin for W… wordfence
6e770e98-3c13-4e37-b51b-4c39bce2cb42
< 5.9.3
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
6e728023-d5da-44cc-bc13-68a5aa63a8a5 MEDIUM 6.4 The Custom Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8 … wordfence
6e5a4ebe-5d01-4d5e-b62b-a264b61fc6ee
< 1.1.0
MEDIUM 6.4 The CPO Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versi… wordfence
6e50081f-6658-4cc7-bf0a-d04464820926
< 4.15.0
MEDIUM 6.4 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
6e3ae3c6-a7d1-46f0-a006-996c1fbe7c7e
< 12.9.0
MEDIUM 6.4 The GreenShift - Animation and Page Builder Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
← Prev 634 635 636 637 638 639 640 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top