🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 653 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
60a35848-1fdd-44c0-a5d4-92abf637e15c MEDIUM 6.4 The Responsive Mobile theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
60922f97-0155-43b5-921c-0ffb288a1d2f
< 2.4.20
MEDIUM 6.4 The Rife Free theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4… wordfence
6077096a-297c-4f15-b52c-ae0532bfece3 MEDIUM 6.4 The Nativery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.1.6 d… wordfence
606a5fe1-d755-4ec0-843b-da3a033b73cf
< 3.0.8
MEDIUM 6.4 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
6065d77d-33ca-4f54-b485-ff1ce71b5e2b MEDIUM 6.4 The WP-Table Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in vers… wordfence
6061e628-4616-4002-950c-62d4a69c5918 MEDIUM 6.4 The Topbar ID for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
605b49a9-caa2-4bcd-8849-eb777b03ab01
< 3.8.0
MEDIUM 6.4 The Quill Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.… wordfence
60564e6b-9eea-4bba-b9b9-391a0f37cc95
< 5.1.1
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
6054a885-e67a-4731-93ea-64d7f90d9ea8
< 2.5.11
MEDIUM 6.4 The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id', 'mixColor'… wordfence
604975b9-fe2f-4d8f-af13-995f08d72e8f
< 8.3.6
MEDIUM 6.4 The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_sty… wordfence
60440b26-1c0b-4fd0-a74a-ff5900d0e9b8
< 4.40
MEDIUM 6.4 The Click to Chat – WA Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [chat] shortco… wordfence
604123f4-9247-489a-8fc8-478bfc697c7f
< 2.1.7
MEDIUM 6.4 wordfence
602c8145-dcf7-4844-8e54-bc50efa307f4
< 4.7.1
MEDIUM 6.4 The Contact Form Clean and Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
602b3b9c-76a7-4b0b-8aad-e554c2fd6910 MEDIUM 6.4 The Comments by Startbit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vivafbcomment' shortcode… wordfence
602ae805-a6a6-48bd-bd2a-00fafadfdce4 MEDIUM 6.4 The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'marketplace' s… wordfence
602a8030-087b-459f-b649-b4116404cf3e
< 28.0
MEDIUM 6.4 The WordPress + Microsoft Office 365 / Azure AD | LOGIN plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
601974c3-65d0-422d-ba59-7ff65fe2a976 MEDIUM 6.4 The Add Ribbon Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
5fe317a6-a391-441a-aac8-c8fa57e73169
< 5.1.17
MEDIUM 6.4 The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner… wordfence
5fcf692f-dbcc-486e-8102-121920ee65c1 MEDIUM 6.4 The Melos theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.0 due t… wordfence
5fbc0866-1e9d-457a-8ef3-fb046c89c1dd
< 3.8
MEDIUM 6.4 The Easy SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in … wordfence
5fb52c19-6816-423d-ab3a-6b5b2ff21e03
< 2.3.1
MEDIUM 6.4 The Snillrik Restaurant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'menu_style' shortcode… wordfence
5fb089ba-d66b-4cf4-a0cc-22cb76358b5e
< 4.9
MEDIUM 6.4 The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
5fab1ae8-2aa4-452a-a594-64088c92b5c3 MEDIUM 6.4 The NOO Timetable plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
5faaf7d1-2012-42d5-affa-a5ff3388d25a
< 4.7.34
MEDIUM 6.4 WordPress Core is vulnerable to Stored Cross-Site Scripting via the emoji settings element in all versions up to, and in… wordfence
5f963abe-d99e-48af-82c2-fba242b68608 MEDIUM 6.4 The Keymaster Chord Notation Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
← Prev 650 651 652 653 654 655 656 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top