🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 645 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
674e6722-d293-4572-80bf-984e74c3e33f
< 7.6
MEDIUM 6.4 The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in a… wordfence
6748841a-0984-4840-90ba-0eeff8564198
< 1.2.2
MEDIUM 6.4 The SALERT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, a… wordfence
6743a762-6d40-4ed9-95f2-f1b405683f26 MEDIUM 6.4 The WP Company Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the '… wordfence
673f0910-8121-4344-b756-2ed5418fdc6b MEDIUM 6.4 The Infinite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘project_url’ parameter in all… wordfence
672c7b4f-73f3-4133-8716-7733848298bd
< 2.3
MEDIUM 6.4 The Essential Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
6720e68e-16fc-48c2-ad56-1f44a3e78bb2
< 2.5.8
MEDIUM 6.4 The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and inc… wordfence
670ea03e-2f76-48a4-9f40-bc4cfd987a89
< 1.1.4
MEDIUM 6.4 The Video PopUp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'video_popup' shortcode in version… wordfence
67050673-73f5-4fc5-a9fc-576ab7ebd7a9
< 3.1.3
MEDIUM 6.4 The WP Image Mask plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.… wordfence
6700e926-21c1-45c9-bca9-62ef0218e998 MEDIUM 6.4 The Dynamic Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dfiFeatured’ p… wordfence
67001e61-c7f5-46bc-9d32-b121ce5d6fd5 MEDIUM 6.4 The esri-map-view plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's esri-map-view short… wordfence
66f71440-59f4-4de4-b008-20bec4820489 MEDIUM 6.4 The ElementsCSS Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
66edd8e5-1d5e-425d-a4f4-5359683c1e36 MEDIUM 6.4 The Simple Vimeo Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ylwm_vimeo’ sh… wordfence
66e55302-f889-4054-817f-aadbdd3c88de
< 4.1
MEDIUM 6.4 The Get Custom Field Values plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Meta fields in … wordfence
66dc7618-3d84-4a55-9bed-0f41415ed9e9
< 3.0.0
MEDIUM 6.4 The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScri… wordfence
66db1cd8-92c7-4d12-9f49-6fa5fbc98d6c
< 1.9.3
MEDIUM 6.4 The WP Last Modified Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
66d77518-a258-4e79-b483-275855c0a416
< 3.19.20.1
MEDIUM 6.4 The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ulti… wordfence
66cad18d-a433-47f1-9cb6-c619c8717a0d
< 3.6.2
MEDIUM 6.4 The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ paramet… wordfence
66c3c02c-0ef4-4d71-97fa-f7b786ae64b9 MEDIUM 6.4 The WordPress Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
66c0a19a-d94f-4de0-85a8-de7c7e489e33
< 1.0.8
MEDIUM 6.4 The Blossom Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in ver… wordfence
66bf7ac2-8f6b-4064-9474-f0f4192a8b33 MEDIUM 6.4 The WebP & SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver… wordfence
66b86375-81e3-4ac8-90e3-8ae34c28c1c2 MEDIUM 6.4 The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its sett… wordfence
66b1f597-f357-4525-8c67-e0be3a07bcfa
< 5.9.8
MEDIUM 6.4 WordPress Core is vulnerable to Stored Cross-Site Scripting via the arrow navigation block attributes in versions betwee… wordfence
669e3015-b64c-440d-bc06-db4828c07196
< 4.2.7
MEDIUM 6.4 The Puzzles theme for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and inclu… wordfence
668621b0-67ef-44fc-a126-e8c4e372666e
< 1.13.7
MEDIUM 6.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in a… wordfence
667d964a-dba6-424a-b3f5-af433616c132
< 2.9.1
MEDIUM 6.4 The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cat_title’ parameter … wordfence
← Prev 642 643 644 645 646 647 648 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top