ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 651 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
62475d8f-a0f6-45ab-abd0-ad24e1887c91
< 1.3.1
MEDIUM 6.4 The Download Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'download-at… wordfence
6245d74b-89ad-4229-8c99-dbfeaa048400 MEDIUM 6.4 The Easy Bootstrap Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'theme_hrrule' fu… wordfence
623c2cd3-bd19-41f3-9633-956cdf141850
< 1.46
MEDIUM 6.4 The Unlimited theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.45 du… wordfence
62388f45-2f13-45c8-b2a0-dbeb6ec76244
< 3.3
MEDIUM 6.4 The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
622b9b46-774d-4251-9a79-73e5b398de57
< 45.7.0
MEDIUM 6.4 The Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages pl… wordfence
620f251e-1e14-4ec7-a47e-27a5e9101f73
< 2.0.6
MEDIUM 6.4 The Responsive Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
620bd934-327e-4509-a5e0-b910654af29b
< 3.7.8.2
MEDIUM 6.4 The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
6203a15d-f90f-4147-8e43-afc424bbb750
< 1.0.15
MEDIUM 6.4 The Template Kit – Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template upload fu… wordfence
61fce18a-44ec-442f-879e-f4ceab93d972
< 3.0
MEDIUM 6.4 The QS Dark Mode Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ve… wordfence
61f63fc3-90c1-42de-8db0-c99abc90369f MEDIUM 6.4 The iframe Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0… wordfence
61f27c69-a044-4749-b553-899580c9f06a
< 3.1.1
MEDIUM 6.4 The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… wordfence
61e6a0db-0af5-4b26-9d16-5e5663500f56
< 2.4.0
MEDIUM 6.4 The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to Se… wordfence
61e375e9-0d68-4a16-9a93-4277d51b6b90
< 1.1.2
MEDIUM 6.4 The ConvertCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
61d23b9f-7e84-4a24-acaf-e96a87e1ea7f
< 5.7.0
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
61d1bc0e-f66f-4bc3-9dfe-2fa19f07999f
< 4.16.6
MEDIUM 6.4 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
61c71bbf-ddae-4f35-ac8d-9753fb3fb67f MEDIUM 6.4 The Ads by datafeedr.com plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in v… wordfence
61c3a517-70c8-4fc2-b8d6-1dcb2ad811d8
< 1.5.8
MEDIUM 6.4 The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
61ab7a28-bcca-41ff-89d1-c083c6b0d39f
< 7.5.0
MEDIUM 6.4 The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
61aaeca4-6b5c-4b00-ab71-bba976d9e1b5
< 1.0.11
MEDIUM 6.4 The Lucky Wheel for WooCommerce – Spin a Sale plugin for WordPress is vulnerable to Reflected and Stored Cross-Site Sc… wordfence
61a643d6-30db-4b9c-98b3-514b616fbd35 MEDIUM 6.4 The Kopa Nictitate Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
619ca4b6-95bb-4c87-b8db-78e6d6b79384
< 1.3.8
MEDIUM 6.4 The Social Sharing (by Danny) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dvk_so… wordfence
6199b852-3270-4456-934b-68c3ef11b9e5
< 3.15.6
MEDIUM 6.4 The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Module Title’ … wordfence
61901d83-0d05-4be8-a318-43bea086293a
< 3.7.0
MEDIUM 6.4 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
618f5577-4214-45f2-aaa6-e34fbe68aff2 MEDIUM 6.4 The UniTimetable plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,… wordfence
618c72b1-363b-41ad-939d-ab2a3b4d579c
< 1.3.8
MEDIUM 6.4 The Black Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i… wordfence
← Prev 648 649 650 651 652 653 654 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top