🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 642 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
69ba1a39-ddb0-4661-8104-d8bb71710e0c
< 3.1
MEDIUM 6.4 The Interact: Embed A Quiz On Your Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… wordfence
69b9d4e1-895b-4199-bc4e-489afd9d36eb
< 1.14.1
MEDIUM 6.4 The Admin Menu Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parame… wordfence
69b173ec-f7e9-4473-9b85-9a204a51cdf5
< 11.6-RC5
MEDIUM 6.4 The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via term descriptions in versions up to,… wordfence
69ab404b-1c2f-441b-8622-3cf830587d95
< 3.2.20
MEDIUM 6.4 The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
69aa4fd2-e331-4aa6-b8d1-b81007496357 MEDIUM 6.4 The Spark Multipurpose theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
69a14e2f-442e-421c-bf5d-0bff3b822911 MEDIUM 6.4 The GivingPress Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
699e41ad-1991-4100-9ef2-caea7743e45b
< 6.4.16
MEDIUM 6.4 The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direct… wordfence
699459a1-d407-4561-9d08-dd5d918ea601 MEDIUM 6.4 The Ajax Domain Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
69938f8a-cd43-426c-8746-0c7dc1d65582
< 1.2.9
MEDIUM 6.4 The REVIEWS.io plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.8… wordfence
697e8954-5adb-472a-a961-4e14f22d3b66
< 1.16.9
MEDIUM 6.4 The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in version… wordfence
6979f943-f348-4750-932f-54f0011cd23c
< 6.0.12
MEDIUM 6.4 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Server-Side Requ… wordfence
696c379a-c5a4-489f-8363-8aea9a4da814
< 5.6.12
MEDIUM 6.4 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… wordfence
69695e2e-2086-4d50-8518-0b2f5ab9ea56
< 2.7.3
MEDIUM 6.4 The myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wrapper attribute in versions up to, an… wordfence
6963b3ed-1b88-49bb-aa2e-99905c14f4c6 MEDIUM 6.4 The UpQode Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) i… wordfence
695563a6-ced9-4951-bc92-0b59a374673f
< 2.3.25
MEDIUM 6.4 The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all ver… wordfence
6953dea2-ca2d-4283-97c2-45c3420d9390 MEDIUM 6.4 The WP Responsive header image slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sp_responsi… wordfence
6921da1b-e63d-479a-9786-9b1bd8201d69 MEDIUM 6.4 The Mosaic theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the them… wordfence
6921c5a7-4895-40f0-99c4-90f78416820d MEDIUM 6.4 The Team plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, a… wordfence
691f86c2-efcd-43c2-8e7f-4cd5258014b2 MEDIUM 6.4 The Smart Mockups plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
691962c2-e67f-4f6e-9002-6f2a4ccbbdee
< 2.2.5
MEDIUM 6.4 A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation… wordfence
6915931e-fcad-4eca-9be5-f0b8f5c4aec2
< 4.8.14
MEDIUM 6.4 The Slider Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.8.1… wordfence
690fd38c-0e12-45f3-9055-51252e4809b1
< 2.7.9.9
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title … wordfence
690e7f00-d9db-4912-9438-7fcbcb026800
< 3.0.0
MEDIUM 6.4 The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored C… wordfence
68fd5e6f-9883-4e8f-9c4f-5905b487629a MEDIUM 6.4 The MS-Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in versions up… wordfence
68fb1fd3-16aa-467f-b5f6-a6126b05e088
< 3.2.7
MEDIUM 6.4 The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
← Prev 639 640 641 642 643 644 645 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top