πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 638 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6e3ae1ab-f7d1-40d8-9f35-04d1706d4134
< 1.0.7
MEDIUM 6.4 The Ekiline Block Collection plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
6e363a62-8d31-4140-878b-5034d6c7b6a1
< 3.2.94
MEDIUM 6.4 The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm… wordfence
6e330894-9a15-4ce3-b388-90fda3d98f8b MEDIUM 6.4 The External Media without Import WordPress plugin through 1.1.2 does not have any authorisation and does to ensure that… wordfence
6e2f3d0a-08b3-471f-9e59-3adcaeab95bc MEDIUM 6.4 The Awesome Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
6e2d0b38-8241-456f-a79b-5d31132b3233
< 4.10.22
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Setting… wordfence
6e21a429-d77e-4a6c-a182-18e51148523c
< 1.8.3
MEDIUM 6.4 The Product Catalog Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
6e185479-843c-4748-83e5-ae0b300c3fc7 MEDIUM 6.4 The Easy Map Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in all … wordfence
6e0bdbba-2b67-42b9-8c26-115d472aed0e
< 3.2.5
MEDIUM 6.4 The Starter Templates (free and premium) plugin for WordPress is vulnerable to Server-Side Request Forgery in versions u… wordfence
6e0591f3-cb6b-4345-93ee-4ab7e01da19a MEDIUM 6.4 The Image Hover Effects Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
6e01ae00-0d07-4e9a-928e-e10cf679df2e
< 2.1.10
MEDIUM 6.4 The DethemeKit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the De Product Displa… wordfence
6dfe91d5-305b-414a-bbed-23c089be6176 MEDIUM 6.4 The "Gallery Bank – WordPress Photo Gallery Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
6dea5fd0-4996-4cd2-9775-7008b92c7224
< 0.9.4
MEDIUM 6.4 The Dropdown Multisite selector plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 0.9.… wordfence
6de4c2bb-a9dd-4de5-89ef-0ed8fde2514c
< 5.4.4
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
6ddab986-c017-475a-ad92-fa4221d6068c
< 2.2.94
MEDIUM 6.4 The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
6dd14860-2cf5-45ec-a1d6-69e43ecdb3be
< 5.2.1
MEDIUM 6.4 The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all… wordfence
6db8742c-b51e-4f86-9ec0-e2166920086f MEDIUM 6.4 The Stylish Internal Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
6db022e7-d0a7-4c32-87b4-7d9a87c4542d MEDIUM 6.4 The Ajax WP Query Search Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
6dac6353-9e70-482d-b54b-ffde661b212c
< 6.0.6
MEDIUM 6.4 The OSM - OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'osm_map' sho… wordfence
6d9431b3-d37e-4d19-b07d-d5357affe346
< 1.6.30
MEDIUM 6.4 The iPanorama 360 WordPress Virtual Tour Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
6d8b2ec1-a76b-42df-8540-4aecaa35efd3
< 4.2.2
MEDIUM 6.4 The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
6d872144-f028-49fa-beac-e315fdea39df MEDIUM 6.4 The RSVP ME plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.9.… wordfence
6d833338-a343-446f-a3f1-cb5e2cff6585
< 1.3.1
MEDIUM 6.4 The Horoscope And Tarot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'divine_horos… wordfence
6d7bd36a-ee41-4121-85b8-f234fd7e5c6e
< 3.6.1
MEDIUM 6.4 The Open Source Genesis Framework theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's short… wordfence
6d5f3b7e-b36f-47a5-9e24-2e9bc17f6cc7
< 1.5.5.2
MEDIUM 6.4 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of… wordfence
6d5c17cb-98a9-45f0-b94f-02b48193949f MEDIUM 6.4 Cross Site Scripting (XSS) vulnerability in the Larsens Calender plugin Version <= 1.2 for WordPress allows remote attac… wordfence
← Prev 635 636 637 638 639 640 641 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top