🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 647 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6593b0de-db7a-4b7e-bd74-cc2b1e36ac60
< 1.2.1
MEDIUM 6.4 The EmbedSocial – Social Media Feeds, Reviews and Galleries plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
658fdcf6-17e0-4cc7-accd-32c4e1e02779 MEDIUM 6.4 The Codeless Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
6571a899-f217-434f-bbed-b1faf77a8d8b
< 4.25.2
MEDIUM 6.4 The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 d… wordfence
656c6236-55e6-4989-8f3d-2d2f81ab0093
< 2.3
MEDIUM 6.4 The WP Masonry & Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wmi… wordfence
656bf2b4-1930-4e96-b92b-01593889a43f
< 3.4.19
MEDIUM 6.4 Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inj… wordfence
65645065-5c17-45f5-9741-26aa2b5d8815 MEDIUM 6.4 The Table of Contents Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
655cd6ec-088f-4610-ae7f-76a959c290af
< 3.0.8
MEDIUM 6.4 The Edwiser Bridge – WordPress Moodle LMS Integration plugin for WordPress is vulnerable to Server-Side Request Forger… wordfence
655077b2-7152-4fc6-845d-068a5af730bb
< 5.3.4
MEDIUM 6.4 The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.3… wordfence
65504747-7f1b-43f9-be4d-48b9547e7c45
< 3.7.2
MEDIUM 6.4 The Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) plugin f… wordfence
6543e6e2-e052-466e-ad19-656fd8d01805
< 2.5.52
MEDIUM 6.4 The Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder plugin for WordPress is vulnerable to Stored Cross… wordfence
6543b8ad-e3f3-43c7-93f9-23f7df07e391 MEDIUM 6.4 The StageShow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘anchor’ parameter in all ve… wordfence
65395034-0b20-462c-93ee-e755e5c888a4
< 3.2.12
MEDIUM 6.4 The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Custom Fie… wordfence
651a7036-d421-41b7-91db-102e60d8274e
< 1.54.1
MEDIUM 6.4 The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sas… wordfence
650b5677-7c70-415f-81bf-12514393e4c9
< 4.8.9
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AI features all… wordfence
6500b559-4c26-47e8-b131-100ece3ca3bd MEDIUM 6.4 The Partnerský systém Martinus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mar… wordfence
64fe64aa-4f55-470d-960b-3b39a4912090
< 1.7.2
MEDIUM 6.4 The SiteGround Email Marketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
64f3d36c-8211-4360-9235-3020395891a1
< 1.5.7
MEDIUM 6.4 The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
64f30329-ecf2-4e30-bc23-9d447e239e08
< 5.5.4
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bt_bb_tabs' shor… wordfence
64f11bc9-88b5-43d5-bc76-129dc5909210
< 3.5.5
MEDIUM 6.4 The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem… wordfence
64f04129-c833-4c2e-a00d-d4e8e435f4a5
< 2.25
MEDIUM 6.4 The PlayerJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.24 du… wordfence
64ed8547-0dc1-4f0a-8b0b-27ce20b8bbd6
< 2.4.6
MEDIUM 6.4 The W4 Post List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block options in versions up to, … wordfence
64d6099e-2435-4a3a-9dcc-dba4a674c711
< 2.0.7
MEDIUM 6.4 The Top and footer bars for announcements, notifications, advertisements, promotions – YooBar plugin for WordPress is … wordfence
64d4fec3-2477-4b0a-b05f-4836563fb4c0 MEDIUM 6.4 The Advanced Blog Post Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
64d2d161-678a-4c0a-b0c5-c28a29a66a5b
< 2.6.0
MEDIUM 6.4 The Real Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in ve… wordfence
64d0c9f4-bc44-4349-977a-2ba3f12d7398 MEDIUM 6.4 The iframe to embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
← Prev 644 645 646 647 648 649 650 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top