πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 640 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6c1b4332-9cf0-415d-acf5-2781364ca337 MEDIUM 6.4 The Mini twitter feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
6c057a98-4a8d-408a-b6a4-3c322bfa0cdf MEDIUM 6.4 The Xavin's Review Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xrr'… wordfence
6c021296-e0e8-481d-a46d-a97934492857
< 3.3
MEDIUM 6.4 The News & Blog Designer Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortco… wordfence
6bfda384-2b39-471d-bf2a-4a8f580ddd1a
< 1.8.12
MEDIUM 6.4 The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1… wordfence
6bf78fbf-c386-4961-8d41-dbdd5c98cb5f
< 1.4.15
MEDIUM 6.4 The Open User Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
6bf534ba-1288-4fa5-bdfb-de62e751e5c2
< 0.4.0
MEDIUM 6.4 The Arena.IM – Live Blogging for real-time events plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… wordfence
6bf0eef5-9276-4367-8451-017c509e443d MEDIUM 6.4 The XO Event Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xo_event_field… wordfence
6be74779-4db7-4d44-a706-285375f4fec9
< 4.8
MEDIUM 6.4 The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `geojsonmarker`… wordfence
6bd69711-8303-4086-87c3-eb2935a89aff
< 1.3.7
MEDIUM 6.4 The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in al… wordfence
6bd15878-a290-4613-83d9-011d60bb0233 MEDIUM 6.4 The Zooom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zooom' shortcode in all ve… wordfence
6bcd770c-a93e-4622-8c19-d0c64aad9768
< 4.0.0
MEDIUM 6.4 The Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider WordPress Plugin plugin for WordPress is vulnerabl… wordfence
6bcb7d69-a444-4f45-a81d-631d95ec2a60 MEDIUM 6.4 The Mini Loops plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.1… wordfence
6bb3ef25-241b-42e5-824a-163fde1ede08
< 1.4.3
MEDIUM 6.4 The Themify Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
6baa44c7-1c13-45ad-9fb5-da06933f3cd0
< 1.3.5
MEDIUM 6.4 The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button wid… wordfence
6ba2738c-c1dd-4d4f-ab11-6c739e53c4a6 MEDIUM 6.4 The yPHPlista plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.1 … wordfence
6b8b94fc-9ae7-47f3-b804-92d0948b662e
< 1.0.4
MEDIUM 6.4 The Gumlet Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gumlet' shortcode i… wordfence
6b89faf8-56b3-4a2d-b890-72242a7fa033
< 20250423
MEDIUM 6.4 The Simple Blog Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
6b6f6f93-4c24-4b81-bd5d-470f6dccab92
< 7.1.0
MEDIUM 6.4 The WP Shortcodes Plugin β€” Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
6b6dc426-7066-46fb-886a-0bf005829abf
< 3.8.2
MEDIUM 6.4 The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(… wordfence
6b6ab7bc-e815-4b3f-bda1-dd816ca457cd MEDIUM 6.4 The Twitter Cards Meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the twitter_card_type metad… wordfence
6b33c180-10b4-4550-8c24-72c9e53664a5
< 11.9.19
MEDIUM 6.4 The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl… wordfence
6b2f6506-1a45-4967-9972-283505df25af
< 2.11.34
MEDIUM 6.4 The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
6b20bda7-c4dd-4260-94f1-d81515324a54
< 2.6
MEDIUM 6.4 The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
6b065dbe-2218-4599-8c9c-a4b9b6097ec0 MEDIUM 6.4 The HireHive Job Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
6b063d3f-11b3-4609-a7d5-dba961034b45
< 3.2.4
MEDIUM 6.4 The IMPress for IDX Broker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
← Prev 637 638 639 640 641 642 643 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top