πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 641 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6aff1ea6-c6d2-4195-899b-3a038b73a7f0 MEDIUM 6.4 The WooCommerce Bookings Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
6af20a2c-065c-48d5-a95c-2883ceeb50c6 MEDIUM 6.4 The Add Widgets to Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
6adf6f3b-aff0-4495-92a4-13855dac5030
< 2.2.5
MEDIUM 6.4 The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading Block in ver… wordfence
6acb99eb-d61c-4d1f-b399-32db07c7e3e7
< 2025.6
MEDIUM 6.4 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe'… wordfence
6abfa01b-e2ec-412c-a17d-e8bd1f5ac228
< 5.3.2
MEDIUM 6.4 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Store… wordfence
6ab0aa86-5df0-4a8a-8a1b-2b4a45ba6c17
< 1.1.12
MEDIUM 6.4 The Easy Media Download plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
6a92b96b-ecbc-4414-8e42-04b5c3a02131
< 5.9.1
MEDIUM 6.4 The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all ve… wordfence
6a8cc968-01a5-45b8-bee8-86c858f86514 MEDIUM 6.4 The WP Games Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [game] shortcode in all ver… wordfence
6a8a5b2b-6cb0-48bf-ba03-d23b1624390d
< 3.1.9
MEDIUM 6.4 The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block a… wordfence
6a7d1469-37c9-4e7b-a4fc-781697e41d11 MEDIUM 6.4 The Simple Sticky Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
6a766255-f144-4c4d-849d-c5c99320962b MEDIUM 6.4 The Turisbook Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
6a714769-589d-49ac-820d-70a2184e6ef4 MEDIUM 6.4 The Google Earth Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
6a6debe9-e0bb-4ea7-be91-757a250515ca
< 1.0.4
MEDIUM 6.4 The Responsive Lightbox2 plugin for WordPress is vulnerable to Authenticated (Contributor+) Stored Cross-Site Scripting … wordfence
6a586bab-df87-4e21-9b05-994c4fc991de
< 6.5.6
MEDIUM 6.4 The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored C… wordfence
6a583966-f58a-41a0-8856-7b7b6a0eb559
< 1.4.1
MEDIUM 6.4 The Medialist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all ver… wordfence
6a39a644-947c-494f-9786-8657d95eaa2c MEDIUM 6.4 The AfterShip Tracking – All-In-One WooCommerce Order Tracking (Free plan available) plugin for WordPress is vulnerabl… wordfence
6a363a7b-16c1-4350-b24c-b3ccf8514a58 MEDIUM 6.4 The BP Profile Shortcodes Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
6a2dab39-f071-4261-a38d-06bd2062673d MEDIUM 6.4 The Best Restaurant Menu by PriceListo plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
6a12acf0-932e-4dff-9da6-9fbace11dbe1
< 2.6.9.1
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Act… wordfence
6a11e7c9-f565-4a8c-895f-425c6654b5a9
< 2.6
MEDIUM 6.4 The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes/s in… wordfence
6a0c948b-7f14-450e-858a-77c1d3dd0761
< 2.10
MEDIUM 6.4 The All in One SEO plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including 2.… wordfence
6a05ed9c-1cd7-44ef-bea1-3e039dbf3500
< 2.0.8.2
MEDIUM 6.4 The BNE Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
6a03556a-feac-4567-9a51-87f93a7ee7f3
< 3.27.10
MEDIUM 6.4 The Print My Blog plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.… wordfence
69f2fc37-4c02-48da-b1e8-350ecc8ba086
< 8.3.7
MEDIUM 6.4 The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post… wordfence
69cc7b6c-b6c2-4bba-afb4-86ba1b36b295
< 9.4.0
MEDIUM 6.4 The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wprm-recipe-round… wordfence
← Prev 638 639 640 641 642 643 644 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top