ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 652 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6189368d-5925-4c84-9f0f-694b9ebcd45e
< 3.9.11
MEDIUM 6.4 The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gu… wordfence
617b2ef0-dc7b-4032-a145-5eaffb8194c3
< 2.1.2
MEDIUM 6.4 The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versi… wordfence
617785d7-90b1-482c-bfff-9b5a63741415 MEDIUM 6.4 The Dealia – Request a Quote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gutenberg block att… wordfence
61705163-54c6-44c6-8a5f-fe16477d9468
< 1.3.2
MEDIUM 6.4 The Gallery PhotoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
615eb349-c5ed-4b6e-bd60-b92b8790427f
< 2.5.3
MEDIUM 6.4 The Skyword API Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skyword_ifram… wordfence
615b4eff-cf92-4d98-857d-c58aa7bd84da MEDIUM 6.4 The Toggle Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6 d… wordfence
61589c29-3f81-49e2-b001-c51892141c76
< 1.1.36
MEDIUM 6.4 The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
614c664b-c95e-49ed-b241-579c32a00bf4 MEDIUM 6.4 The Greek Namedays Widget From Eortologio.Net plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
614bdce2-bd87-4516-b1a5-028ffc08b238
< 7.4.1
MEDIUM 6.4 The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
61488a15-b49f-4381-9a35-746c39f25967 MEDIUM 6.4 The Viitor Button Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' shortcode … wordfence
6126ec74-d522-45ff-aa03-07aad5fb75b9
< 5.81.0
MEDIUM 6.4 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author… wordfence
61206bfb-1669-4c67-a9bd-ba3a20ceb810
< 3.0.15
MEDIUM 6.4 The Culqi plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.14… wordfence
611b88f4-96ae-47e4-8642-e09bee333468 MEDIUM 6.4 The Royal Custom CSS for Page and Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'royal_… wordfence
611871cc-737f-44e3-baf5-dbaa8bd8eb81
< 0.89.4
MEDIUM 6.4 The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' sho… wordfence
6106c972-5475-4c19-8630-3a01edc616ad
< 2.0.6.1
MEDIUM 6.4 The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is … wordfence
60fd38f8-e864-4011-b9f9-b3fef6551175
< 5.5.7
MEDIUM 6.4 The WPML Multilingual & Multicurrency for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
60f16abd-951b-48a0-a363-0221f7e0957d
< 1.32
MEDIUM 6.4 The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget… wordfence
60eda1f3-b54c-419d-8813-be60a35dfa1b MEDIUM 6.4 The Boombox Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
60e4c186-5239-464d-be83-1b873f821b3e
< 2.1.6
MEDIUM 6.4 The All in One SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SEO settings for posts i… wordfence
60de55c6-e4fa-453e-84bd-309f2887e3cb
< 3.4.2
MEDIUM 6.4 The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bsk-pdfm-category-dropdown' s… wordfence
60db100b-7a09-4ac1-81ec-9b400c9cce47
< 2.0.11
MEDIUM 6.4 The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
60c96210-d6ed-4838-b2fc-419e6a68f689
< 3.3.9
MEDIUM 6.4 The Rate my Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and … wordfence
60c0db19-deda-4b95-a341-cf33883dc9b4
< 3.0.9
MEDIUM 6.4 The Yumpu E-Paper publishing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'YUMPU' … wordfence
60ba7f68-1fe1-4349-a3eb-11a63ae11e38
< 1.5.1
MEDIUM 6.4 The Add to Calendar Button for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in v… wordfence
60af0a7c-014b-4f71-9918-7ddc1186bee4
< 3.6
MEDIUM 6.4 The Livemesh Addons for WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
← Prev 649 650 651 652 653 654 655 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top