πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 650 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6318a1cf-716f-450c-a1c2-497de8095daa
< 4.5.4
MEDIUM 6.4 The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
630c89bf-de7a-491f-b2b6-8f573071cf71 MEDIUM 6.4 The Animation Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
62f1635a-cb94-4c5e-a1f6-90a1eeb38968 MEDIUM 6.4 The Unlock Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
62ea9e85-7752-4d0f-aafb-cbbc94294335
< 2.0.1
MEDIUM 6.4 The JS Job Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title parameter in versions… wordfence
62de6922-f3f2-4996-a749-2d6d3a8be042
< 1.3
MEDIUM 6.4 The Royal PrettyPhoto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text parameter i… wordfence
62d32cda-bb6d-4ffa-82b9-f2f6e8d4346f
< 7.4.3
MEDIUM 6.4 The WP Shortcodes Plugin β€” Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
62d1b4a2-5c1e-4381-a455-082bee734ff2
< 2.0.1
MEDIUM 6.4 The WordPress Team Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(… wordfence
62c3f844-ed88-4a6c-a8c2-7b573096ec8b
< 3.8.9
MEDIUM 6.4 The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
62b2113a-70a2-4223-8c6c-6cd15057d72d MEDIUM 6.4 The Seos Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio… wordfence
62ace939-3c14-4e68-897b-ec845182ca50
< 3.12.9
MEDIUM 6.4 The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
62abc1e8-155d-4726-81d3-ed2cc7dd7373 MEDIUM 6.4 The Advanced Recent Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's lptw_recent… wordfence
62a9c9f4-ace4-4029-a720-5ea077e98be4
< 7.4.8
MEDIUM 6.4 The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all … wordfence
62a5ea05-a0d2-4b07-ad57-e8ca88798b71 MEDIUM 6.4 The Creative Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
62a4dd6a-f970-483e-b1a8-d57f604b7b66
< 2.1.6
MEDIUM 6.4 The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
629fdcb5-83fc-4a01-ba20-eea8ef5df24f MEDIUM 6.4 The Kings Tab Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
629fafeb-5b69-4269-bd98-aaf170d98094 MEDIUM 6.4 The Community Yard Sale plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
62961a07-69df-4586-861d-5fc4fde8aec5
< 0.19
MEDIUM 6.4 The Theater for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
6290559d-5902-455c-bc33-7aa3c820162b MEDIUM 6.4 The Ravelry Designs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout' attribute … wordfence
628b3f53-decd-47ac-a2d1-339ade1e6944
< 5.5.1
MEDIUM 6.4 The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to and including 5.5.… wordfence
62876268-b019-4717-bb8e-36dc4a5ad489
< 4.2.14
MEDIUM 6.4 The WC Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4… wordfence
62813e66-5b1c-4aae-b6e4-37d71515c54c
< 2.6.0
MEDIUM 6.4 The DELUCKS SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.… wordfence
6274adb0-5785-4f8e-b3d2-5d79f08329ec MEDIUM 6.4 The Google Drive WP Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
626c82a1-4157-4294-9563-08accccf2a10 MEDIUM 6.4 The Surbma | SalesAutopilot Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
625d2b09-a6b9-4c0c-8c36-3c565e688aac
< 3.6.9
MEDIUM 6.4 The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Cust… wordfence
6252f038-f3ae-41f1-8a5b-0557d3e1252f
< 1.3.4
MEDIUM 6.4 The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
← Prev 647 648 649 650 651 652 653 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top