🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 648 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
64bffbca-39e9-4430-9dda-e50642f53ed9 MEDIUM 6.4 The Hover Image Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
64bb204e-3fc6-4570-a3ff-aefb72c2822a
< 6.0.3
MEDIUM 6.4 The Poll Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.0.2… wordfence
64b7985e-bb35-4648-8159-4424661b52a9
< 4.1.14
MEDIUM 6.4 The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
64b4faf1-c2f2-43cd-900e-22edce3145a8
< 2.0.11
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in the Temporary Uploads editing functionality (wp-admin/includes/upload.php) i… wordfence
64a15397-0bd6-4be9-90e3-6cb1f56394ad MEDIUM 6.4 The Network Posts Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_height’ p… wordfence
649545c8-e6a2-4587-a439-17081f389d46 MEDIUM 6.4 The WP-Revive Adserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprevive_asyn… wordfence
64852bc8-aeba-458d-9235-94bd4c4ec429
< 6.7.11
MEDIUM 6.4 The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu… wordfence
647f0b46-ac12-445b-9d41-66eba3eb2b1a MEDIUM 6.4 The Embed Twine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embed_twine' shortco… wordfence
64694d30-a780-4655-9a65-af1cfa542ccc
< 2.4
MEDIUM 6.4 The Blog Designer - Post and Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's s… wordfence
64624d4c-3ffb-4516-a938-0accde24c79f
< 1.2.15
MEDIUM 6.4 The Photoswipe Masonry Gallery WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and s… wordfence
645552ef-84aa-4f51-93d4-cb85c43fed58
< 1.1.8
MEDIUM 6.4 The Photospace Responsive plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1… wordfence
64534424-709f-4bd2-aa25-638cf05e47f3 MEDIUM 6.4 The Drozd – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
64480862-c076-4ea9-a03b-9aed81f876d5
< 2.7.16
MEDIUM 6.4 The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the settings of… wordfence
6439ea1f-78de-432f-bb1a-9ffc731a4ff4
< 1.0.0
MEDIUM 6.4 The PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions… wordfence
64399c1c-ea82-483b-b320-3c6f2cb010b3 MEDIUM 6.4 The My Album Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style_css' shortcode att… wordfence
642400f6-9579-4065-a5a5-6fec23131778
< 1.3.2
MEDIUM 6.4 The Task Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Add a comment' section i… wordfence
641f2808-540b-446a-9bf0-5bd57f7fabdf MEDIUM 6.4 The ABG Rich Pins plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
63feaadc-27f2-4e87-892d-07595e08021a
< 3.6.1
MEDIUM 6.4 The Ghost Kit – Page Builder Blocks, Motion Effects & Extensions plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
63f43fb9-3d8d-48ea-b760-0e068570b16d
< 1.26.1
MEDIUM 6.4 The Happyforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.26.… wordfence
63f26380-0bc2-4fe7-9e9d-05c688c201f9
< 18.01
MEDIUM 6.4 The Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar blo… wordfence
63ef7383-d684-473b-aa0f-45027ef245f6
< 1.13.6
MEDIUM 6.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ paramet… wordfence
63ed73c9-2b61-4811-ba7f-1803982f17bc
< 3.14
MEDIUM 6.4 The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode… wordfence
63e00072-0e3c-4b1c-8c30-3f94d5f538f0 MEDIUM 6.4 The Genemy theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.6.… wordfence
63d73de6-56ac-41ab-a673-4e379eeed26c
< 1.0.3
MEDIUM 6.4 The Saphali LiqPay for donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saphali_liqpay'… wordfence
63cab921-60fa-42c5-ad0d-69de8cc91332
< 5.6.9
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcod… wordfence
← Prev 645 646 647 648 649 650 651 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top