🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 639 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6d58355d-2762-4ecc-aec2-52a1e3323017
< 4.5.5
MEDIUM 6.4 The WP-Appbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's appbox shortcode in all… wordfence
6d53de57-13eb-4f27-8dff-1a7027e31edc
< 5.0
MEDIUM 6.4 The Smart Agenda plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.9… wordfence
6d4b0434-61ca-47b1-9119-7208283f916f
< 4.6.0
MEDIUM 6.4 The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ paramet… wordfence
6d3c51e9-d66c-434f-8b01-e5af258c9a8b MEDIUM 6.4 The TemplatesNext OnePager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and … wordfence
6d1b948a-7a7e-4bdf-af1d-559f34d4baa3
< 3.11.2
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attri… wordfence
6d0fff4d-e9fa-45ef-9593-753b40a71d38
< 2.0.5
MEDIUM 6.4 The Basil theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `post_title` parameter in all version… wordfence
6d06d721-ab48-43ae-81d6-bd0b3177a7bf
< 4.5.2
MEDIUM 6.4 The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ para… wordfence
6cee8cd9-7fa9-4154-9d74-ab54da18e521 MEDIUM 6.4 The Easy Textillate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
6ce726da-4860-4809-b579-9ec0d31a2fb1
< 6.5.4
MEDIUM 6.4 The Easy Social Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fb_appid' parameter in… wordfence
6cdbc865-2566-419c-a54f-f719b64bf149
< 2.0.15
MEDIUM 6.4 The Envato Elements – Photos & Elementor Templates plugin for WordPress is vulnerable to Server-Side Request Forgery i… wordfence
6cd5d1c7-4be2-457b-bd28-0cb76e9800e5
< 5.4.6
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘percentage’ paramet… wordfence
6cc4a67b-81fa-4ef6-9167-eab5cb9002ec
< 4.8.9
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Price List' element in … wordfence
6cc2dba8-a058-4a1e-a975-9c04639a4f50
< 1.1.9
MEDIUM 6.4 The BuddyPress Activity Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
6cbf9636-9d9d-44d4-b873-8920f2dbb846
< 2.3.0
MEDIUM 6.4 The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
6cbe4748-6e87-4332-b84f-615aec67bcec
< 2.0.6
MEDIUM 6.4 The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content … wordfence
6cae72cd-8a51-4e26-8ba2-c04c7d95faf7 MEDIUM 6.4 The Video Embeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.1… wordfence
6ca4dff0-ca3a-44cf-a30b-36b31d2848ab
< 1.3.42
MEDIUM 6.4 The Materialis Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's materialis_c… wordfence
6ca2d1d4-fcf8-4943-b9c5-9560968ae2d8 MEDIUM 6.4 The Add SVG Support for Media Uploader | inventivo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
6c9f5515-cdf5-4883-bdeb-1de53bcc615a MEDIUM 6.4 The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode att… wordfence
6c87204d-6697-4d06-aad2-279fa95f503a
< 1.3.8
MEDIUM 6.4 wordfence
6c51a97f-8258-4b55-bcfd-cd1cbca08f01
< 1.0.1
MEDIUM 6.4 The Advanced Data Table For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
6c4c2a2e-d21b-437f-a8a0-508e4caf33bc
< 5.11.1
MEDIUM 6.4 The TheGem Theme Elements (for Elementor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
6c3954af-f7db-495c-b6f0-49f24d6f4b18
< 1.1.5
MEDIUM 6.4 The GamiPress – Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's gamipress_link… wordfence
6c384f05-96dd-47bb-822d-16212527091a MEDIUM 6.4 The Image Hover Effects for Elementor with Lightbox and Flipbox plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
6c29bd91-e7b1-4c26-90bf-4a77bd67edbe MEDIUM 6.4 The Responsive Mobile-Friendly Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
← Prev 636 637 638 639 640 641 642 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top