πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 649 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
63bb9298-dd00-49a9-aea2-2797f0974d7f MEDIUM 6.4 The SnapWidget Social Photo Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
63ba4880-9fbb-42e3-a8db-8115eb832b13
< 1.5.141
MEDIUM 6.4 The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's … wordfence
63ade911-f9e7-4b1c-87c8-78e7664feff7
< 5.0.3
MEDIUM 6.4 The Trackserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tsmap' shortcode in … wordfence
63a9fd8b-c71a-4945-bc02-1761331df832
< 4.6.2
MEDIUM 6.4 The WordPress Simple PayPal Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcod… wordfence
63a3fc17-8a1e-4791-9d5a-33080112b633
< 2.9.1.2
MEDIUM 6.4 The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.… wordfence
639c260d-12f3-446e-8668-1de72fc759b9 MEDIUM 6.4 The Embed documents shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
639693b6-369e-457e-a37e-30bdb8ea7275
< 3.29.1
MEDIUM 6.4 The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
639410e2-aecd-4545-aa3e-c795c663e8f0
< 4.0.0
MEDIUM 6.4 The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
6390dba6-423b-48be-b5f0-1018d94f4a32
< 1.2.0
MEDIUM 6.4 The ThemeMakers PayPal Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypa… wordfence
638d8ef6-dab0-4cfa-8ecc-af2ded3c6d79
< 2.4.2
MEDIUM 6.4 The eHive Objects Image Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ehive_o… wordfence
638d18ea-1ff6-432d-abe5-38e84916c106
< 1.5.0
MEDIUM 6.4 The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cro… wordfence
638a6819-5105-491f-b5e4-ed6a495434ec MEDIUM 6.4 The Animate plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.5.… wordfence
637f07c6-68cd-4ac6-83fd-65dbaab882fc
< 2.6.2
MEDIUM 6.4 The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fiel… wordfence
637972a3-1936-4add-88a2-3fbafba4b5c8
< 1.4.4
MEDIUM 6.4 wordfence
6367c5fc-f664-4105-a1b7-a93fb0a2392b
< 6.4.10
MEDIUM 6.4 The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for W… wordfence
635e02a8-42f3-4098-aa3e-839099f40bfb
< 1.8
MEDIUM 6.4 The plugin Restaurant Reservations is vulnerable to SQL Injection via an several parameters in versions up to, and inclu… wordfence
635c29d1-3638-464b-9b04-355393eac67d MEDIUM 6.4 The The Pack Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
6351a40d-523d-4edb-acba-5cf048a1014f
< 2.1.0
MEDIUM 6.4 The Easy MLS Listings Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasa… wordfence
634fa1ed-ad6b-4875-b6f9-f20add39dc80 MEDIUM 6.4 The Ayyash Studio β€” The kick-start kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File … wordfence
634e5c33-cd24-46ab-aac0-161eeb28aaff MEDIUM 6.4 The WP Photo Effects plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wppe_effect' sh… wordfence
6348b119-a0dc-40ef-ae62-1de86dcefac7
< 2.0.1
MEDIUM 6.4 The Team Section Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block in all v… wordfence
63458059-c392-4e2b-be8f-cc24771261df MEDIUM 6.4 The bxSlider integration for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
63306df3-4972-426f-bfda-6af75a09971c
< 2.0.31
MEDIUM 6.4 The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜url’ paramet… wordfence
631e1061-50b1-4df2-b876-37b4cd3e2478
< 3.4.9.2
MEDIUM 6.4 The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shor… wordfence
631d200f-7b0b-4105-b91e-030af459ba99
< 3.9.9
MEDIUM 6.4 The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & El… wordfence
← Prev 646 647 648 649 650 651 652 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top