ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 643 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
68f87cc7-fde5-4cd6-ab25-bf05cd3b5cde
< 3.7.33
MEDIUM 6.4 In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the… wordfence
68f75333-5165-42ac-808e-69b20a8d7f19 MEDIUM 6.4 The JB Horizontal Scroller News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
68f470ad-2475-444c-ae9d-8b86a5b8349f MEDIUM 6.4 The Hide Text Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
68e2f8ae-5908-423b-befa-17481418394c
< 1.2.7
MEDIUM 6.4 The Countdown Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
68ddc0a1-2f5a-446d-9d83-b6028d012956
< 3.7.4
MEDIUM 6.4 The WP LiveChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'livechat_email' option in ver… wordfence
68cdbe3e-6169-4177-873d-1028912ecad6 MEDIUM 6.4 The FancyTabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all ver… wordfence
68cabb14-2484-44ed-92ee-9c1d27540d6a
< 1.8.13
MEDIUM 6.4 The Qubely plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.12 du… wordfence
68c6e428-b9cf-442f-a896-a8ceb4b9be0e
< 1.7.1013
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `widg… wordfence
68c190af-6b86-4831-a071-77e30caff912
< 1.9.0
MEDIUM 6.4 The Simple WP Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
68c16098-c01a-4023-972a-d0bc0468a973 MEDIUM 6.4 The MSTW League Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
68b4358d-d4b4-415b-a19f-e58b155ceac9
< 2.3.5
MEDIUM 6.4 The Listamester plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listamester' shortco… wordfence
68ae8404-6dfa-4b13-b2a6-bd4554f1043f
< 1.5.3
MEDIUM 6.4 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… wordfence
6892fefa-3866-4dbf-8604-dd4bc1e7d481 MEDIUM 6.4 The The Awesome Feed – Custom Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's … wordfence
688c04b5-e5fe-4ddf-b253-2418149d9aba MEDIUM 6.4 The ABCBiz Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to,… wordfence
6881c774-a20f-4b18-8ce2-7e60d89073d6
< 2.4.7
MEDIUM 6.4 The Admin Management Xtended plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
687ffac2-1f07-4adb-ba12-5f2ea357ea7e MEDIUM 6.4 The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attribute… wordfence
687c86af-915e-4028-910e-ab83bcd86a1a
< 7.14.2
MEDIUM 6.4 The ExactMetrics plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.1… wordfence
687ae27f-678e-46aa-bb32-24ab5ad771ab
< 1.1.7
MEDIUM 6.4 The Brand theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.6 due t… wordfence
686182c4-f6bc-41a2-a665-efce3a30c5fb MEDIUM 6.4 The Easy FAQs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.1 … wordfence
68530904-22d2-4228-b9f2-76f5ee1fd541
< 2.8.4
MEDIUM 6.4 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
684a1e8e-30f2-47dd-9df6-145198030c52
< 6.2.3
MEDIUM 6.4 The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the update_layout function in versions up… wordfence
683edf03-b3ea-4de9-91d8-c4a556739f7f
< 2.0.7
MEDIUM 6.4 The B Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.6 d… wordfence
6830f98b-21f8-4089-9091-1dcd31697425
< 1.7
MEDIUM 6.4 An issue was discovered in the dark-mode plugin 1.6 for WordPress. XSS exists via the wp-admin/profile.php dark_mode_end… wordfence
68277e73-9ef8-42b9-8f21-8b3a9cd0cb95
< 2.3.2
MEDIUM 6.4 The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
68251e79-d064-4be4-a218-92a03e27b59d MEDIUM 6.4 The Meta Display Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meta Display Block in a… wordfence
← Prev 640 641 642 643 644 645 646 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top