πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 646 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
667b11ff-496f-4560-b751-7bb25bcd7cbb
< 2.5.9
MEDIUM 6.4 The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers… wordfence
667834e3-85c7-44d9-8858-b030c646edd1
< 1.3.18
MEDIUM 6.4 The Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.17 … wordfence
666aea4b-651d-4ab6-8b2e-95f09e5faf71 MEDIUM 6.4 The Text Slider Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
6662fee4-7e04-492f-bf79-2c915da92c92 MEDIUM 6.4 The PriPre plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,… wordfence
6662581b-a057-4b88-951d-824c64f9cdfd
< 0.6.30
MEDIUM 6.4 The YaMaps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
66607be6-cca1-4cbb-b1c0-708d640b1151 MEDIUM 6.4 The Olevmedia Shortcodes for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
66529116-7b0e-4e2f-96f1-a4d91fa7f956
< 2.02
MEDIUM 6.4 The Easy Textillate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'textillate' shor… wordfence
664e5a7a-bb40-4615-9482-a285bed9b23b
< 2.7.7.30
MEDIUM 6.4 The Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
664d22f2-b7a3-42df-9530-4040160ead2c
< 2.6.8
MEDIUM 6.4 The Ajax Archive Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s… wordfence
663c54f4-4ca5-4916-b2a5-de3cabe77f38
< 3.2.4
MEDIUM 6.4 The SupportCandy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2… wordfence
663bd2b2-89ce-4701-9071-200cc86d0a90 MEDIUM 6.4 The Design Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
66334c29-c9d6-48b0-8d6b-bae588da0331
< 11.2.2
MEDIUM 6.4 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
66201d43-9f25-46a8-ac29-0482e8dc5b2e
< 1.9.74
MEDIUM 6.4 The Postie plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.73 du… wordfence
65fc55bb-2b86-466a-b43b-554628283f02
< 1.1.16
MEDIUM 6.4 The LoginPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.1… wordfence
65f49fe0-6aad-445e-a86e-ad1089239303 MEDIUM 6.4 The Empty Cart Button for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
65ee0ac8-3fa0-4a7d-a786-36a914242634
< 2.17.1
MEDIUM 6.4 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
65e34c69-f666-4bae-a086-789b93d15cc2 MEDIUM 6.4 The Void Elementor WHMCS Elements For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
65dffde9-2a50-41fe-bc21-3d0915068887
< 6.1.16
MEDIUM 6.4 The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_name' and 'f… wordfence
65db0063-63c4-400b-9192-ddcc16c0a541
< 3.0.1
MEDIUM 6.4 The Zoho Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versio… wordfence
65d965ac-66ae-4c23-b9c2-335b93a140d9
< 4.2.0
MEDIUM 6.4 The Appointmind plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appointmind_calendar… wordfence
65d8dbff-1402-4a84-808a-49e2a5ab861d
< 6.3.9
MEDIUM 6.4 The Photo Gallery by Ays plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
65d11459-5cad-4d8b-a81d-7f0dd4342a52
< 0.1.10
MEDIUM 6.4 The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'taeggie-feed' short… wordfence
65ae3119-61d1-4ec0-8ba2-352aae5cc834
< 2.2.8
MEDIUM 6.4 The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's visual-link-p… wordfence
65ab07e8-4cba-4d81-8e80-8c6c96c1095e MEDIUM 6.4 The 1app Business Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in ve… wordfence
6594b5ba-57e4-4ef1-93b9-ac1e90ed13be MEDIUM 6.4 The Social Sharing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode … wordfence
← Prev 643 644 645 646 647 648 649 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top