πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 644 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
680c65c4-a7db-4834-abb0-290da33bfb18
< 2.0.16
MEDIUM 6.4 The Cozy Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.… wordfence
68094545-0e2a-429d-95b7-bfa86eca1caa
< 4.0.1.7
MEDIUM 6.4 The WP Adminify – Custom WordPress Dashboard, Login and Admin Customizer plugin for WordPress is vulnerable to Stored … wordfence
6807689f-e78c-4098-a14b-073430d3c52b
< 3.5.11
MEDIUM 6.4 The JetSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.10… wordfence
680219f5-631e-4318-bf1b-598947bec7d6 MEDIUM 6.4 The GetResponse for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
67f405d0-7139-4b5c-ab3c-cd1de5592866
< 9.0.33
MEDIUM 6.4 The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
67f23705-ee04-40a7-a4d9-3bf654a2cb12
< 3.14.2
MEDIUM 6.4 The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
67e3b25e-176f-4a0d-a10d-678ea772ce3c
< 1.5
MEDIUM 6.4 The amCharts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜post_id’ shortcode attribute… wordfence
67dbaf4d-c54c-43ea-8725-3455a4c84e16
< 1.4.2
MEDIUM 6.4 The WPCasa plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.1 due… wordfence
67d112e1-72d3-4ac9-93ca-82a7410cfbbb MEDIUM 6.4 The xili-tidy-tags plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
67bacd52-9d23-4222-a8a7-ae98f66c752a
< 4.3.2
MEDIUM 6.4 The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to Server-Side R… wordfence
67b0f756-9130-402d-9787-78d482fa183e MEDIUM 6.4 The Anber Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $item['button_link']… wordfence
67afe49c-3560-414b-b848-b91a03bf7556 MEDIUM 6.4 The Temporarily Hidden Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'temph… wordfence
67a44d4c-da3f-4c3d-997b-1417c6906a9c
< 4.22.8
MEDIUM 6.4 The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
67981160-6c91-48a4-ba1c-68204d538ed6
< 2.6.9
MEDIUM 6.4 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sto… wordfence
6788b92c-8a2c-4ebb-85ca-eb1fd0f3b0e0
< 1.8.15
MEDIUM 6.4 The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
6786dba1-34cf-467e-9437-d3fadeb020c6 MEDIUM 6.4 The Consulting theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.0 … wordfence
67856d6b-9be9-494a-b713-f36d5e29e7f1 MEDIUM 6.4 The Piotnet Addons For Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
6776b586-95c9-4e67-b7a3-a016e75d77d1 MEDIUM 6.4 The Sketchfab Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
67768957-45be-48d9-ad5e-147290ef4cd5
< 1.0.7
MEDIUM 6.4 The Plezi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'plezi' shortcode in all ve… wordfence
67709117-8912-4c09-afcb-0c07345d00e0
< 4.2.7.5.1
MEDIUM 6.4 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all version… wordfence
676b4768-98ea-4e55-87de-ef7ae1d7a113
< 2025.3
MEDIUM 6.4 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe'… wordfence
676b0348-7ccd-4a14-be84-2497877a1e36 MEDIUM 6.4 The WP Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.0… wordfence
675bf571-eb8b-4c72-9852-b3a2b37b9a04 MEDIUM 6.4 The TR Timthumb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versio… wordfence
675937dc-a032-4bc4-a449-c815fcb12db6
< 3.19.20.1
MEDIUM 6.4 The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ulti… wordfence
6751e9b3-b43f-474a-8733-c337e17ab683
< 1.7.4
MEDIUM 6.4 The Blog Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.… wordfence
← Prev 641 642 643 644 645 646 647 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top