🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 654 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5f958a43-1753-4605-9e98-ba1468f75ab0
< 1.4
MEDIUM 6.4 The XLTab – Accordions and Tabs for Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
5f829d21-5347-46ec-9218-2b3cbe7d7b95 MEDIUM 6.4 The BigBlueButton plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the moderator code and viewe… wordfence
5f78dd75-d853-4b16-843e-e0c9c55a103c MEDIUM 6.4 The File Away plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in version… wordfence
5f6eba90-3e9d-48d0-aae2-81ff216315da MEDIUM 6.4 The Posterity theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8 due… wordfence
5f50e293-aebd-44dd-a692-64dea8f6622f
< 2.8.51
MEDIUM 6.4 The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘… wordfence
5f459033-1c95-4781-93f4-1ee5e310933a
< 1.5.1
MEDIUM 6.4 The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sever… wordfence
5f3f9891-710e-49e4-b388-aa6d99c01840
< 3.1.15
MEDIUM 6.4 The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ao_post_preload' meta value i… wordfence
5f3cd194-3fb8-4dd9-905e-051d5de68b66
< 2.2.0
MEDIUM 6.4 Mine CloudVod plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘audio’ parameter in all ver… wordfence
5f346cc7-92ad-4f76-a71c-864c22ed56b5
< 3.7.8.1
MEDIUM 6.4 The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
5f2435fd-ccd5-4e51-89d7-98cddafac3fd MEDIUM 6.4 The Digi Store theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.4 … wordfence
5f15ffca-bd59-4d07-8d79-2b41c7f6187c
< 3.20.10
MEDIUM 6.4 The Markup Markdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the markdown support in all ve… wordfence
5eeff1c0-2c64-4229-b68a-6865fccf92a2 MEDIUM 6.4 The GMO Font Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
5ee0dd57-6256-4a56-907e-89336f052b6d
< 2.1.7
MEDIUM 6.4 The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
5ec2111a-0f23-48ed-a7a3-54a33e3f4bd9 MEDIUM 6.4 The Grand Restaurant Theme Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in v… wordfence
5ebda2ba-c24f-4f40-8f67-341dacaf907a
< 0.94.0
MEDIUM 6.4 The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
5eb4f996-b74c-495e-958e-7c6fb4eba62e MEDIUM 6.4 The Image Switcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
5ea93a49-0e1a-4a24-8f6b-03e624f517d4
< 3.4.9.6
MEDIUM 6.4 The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpme… wordfence
5e9a8c60-f781-428b-8847-88b671010daf
< 1.2
MEDIUM 6.4 The UseStrict's Calendly Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
5e7fa38f-26ef-4011-af18-c18883159425 MEDIUM 6.4 The Simple Excel Pricelist for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pr… wordfence
5e79bdfe-5b91-4459-9e0f-f25859e4d0ce
< 4.4.1
MEDIUM 6.4 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
5e701eb7-ed9e-464c-bcaa-635710736f7c
< 1.3.0
MEDIUM 6.4 The LIQUID BLOCKS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
5e528d16-4a5d-4ef9-baac-e235fa3b4be3 MEDIUM 6.4 The Jobify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘keyword’ parameter in all vers… wordfence
5e5143f2-6641-4ae3-baa1-e5b83d784799
< 5.0.4
MEDIUM 6.4 Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross… wordfence
5e397c7a-2aef-4c23-a224-e324ea4bb4b1 MEDIUM 6.4 The WPMK Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in … wordfence
5e38ee27-30a4-45be-bab6-a3e65ada215f
< 1.2.8
MEDIUM 6.4 The WP Affiliate Disclosure plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $id variable in ve… wordfence
← Prev 651 652 653 654 655 656 657 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top