πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 655 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5e2f3abd-0a15-4bc1-966a-22d606f3e333
< 3.0.1
MEDIUM 6.4 The Quotes llama plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quotes-llama' short… wordfence
5e18c3b9-0a3a-4f6a-bc22-8022947dd7cb
< 3.1.59
MEDIUM 6.4 The Ditty plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.58 due… wordfence
5e0b3012-dc29-4a15-811b-190b16a0c86e
< 2.0.4
MEDIUM 6.4 The AI Share & Summarize plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 2.0.4 due t… wordfence
5dfaa23f-05df-423c-a5f6-02f2b714b5b6
< 27.5.6
MEDIUM 6.4 The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,… wordfence
5df2f3cc-affc-4549-b59e-d145cce10c79
< 2.0.1
MEDIUM 6.4 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
5dee21da-dd92-41e7-8547-fb49eecec03c
< 3.3.2
MEDIUM 6.4 wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes i… wordfence
5de1b6e2-59a3-41ae-a73c-66a79fbd2316
< 4.2.7
MEDIUM 6.4 The Houzez Theme - Functionality plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
5ddfa2a1-39e1-4ead-85c5-1624749bd353
< 9.8.0
MEDIUM 6.4 The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Video Link values… wordfence
5dd7eb74-20ec-4949-9ba2-34081849d7f7 MEDIUM 6.4 The GC Testimonials plugin for WordPress is vulnerable to Cross-Site Scripting via an unknown parameter in versions up t… wordfence
5dd6a90e-03da-43e5-b975-be8f5aa5fc60
< 3.7.2
MEDIUM 6.4 The NiceJob plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes (ni… wordfence
5db58070-fb0f-4d91-aac4-3c951af66b74 MEDIUM 6.4 The VP Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 d… wordfence
5dabfdab-2c7a-4c9b-9c8f-a93639da1a35
< 2.0.1
MEDIUM 6.4 The Void Elementor WHMCS Elements For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
5da2dac6-940c-419e-853f-6cfd5d53d427 MEDIUM 6.4 The Advanced Menu Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'advMenu' shortcode in ve… wordfence
5da295f3-ac54-4330-ac39-65225adeb93a
< 12.7.0
MEDIUM 6.4 The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via its lightbox rendering code in all version… wordfence
5d9689ed-2be0-4573-a794-2c5bfadafdf5 MEDIUM 6.4 The Testimonials plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.0.1 due … wordfence
5d92687e-cdf2-4dd2-b984-eaf9f0a56625
< 7.0
MEDIUM 6.4 The ND Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nd_options_testimo… wordfence
5d7fd79f-8113-4143-b630-46531e574fc9 MEDIUM 6.4 The Animate Your Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animation-s… wordfence
5d70b447-4f7f-4196-a37b-167679cef229
< 3.6.1
MEDIUM 6.4 The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfilter… wordfence
5d6d9852-424a-4d98-9926-e849bef99c2d
< 1.2.5
MEDIUM 6.4 The Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg plugin for WordPress is vulnerable to… wordfence
5d696d5c-e113-4d41-b077-4eb6b2c93669
< 2.3.3
MEDIUM 6.4 The Pronamic Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
5d44255b-0615-439d-b166-8f1100f53e3a MEDIUM 6.4 The RomanCart Ecommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blclass' attribute (a… wordfence
5d28fd23-fa86-4353-b1b4-af61192f8482
< 5.1.13
MEDIUM 6.4 The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'plan_icons' para… wordfence
5d20eb50-3b54-475f-8a67-8ca61c0474cc
< 1.1.1
MEDIUM 6.4 The Selio - Real Estate Directory theme for WordPress is vulnerable to Stored Cross-Site Scripting via the message textf… wordfence
5d1b419c-2276-415d-8c54-15da9125c442
< 4.10.5
MEDIUM 6.4 The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's liv… wordfence
5d178852-53bc-440b-8217-67ae68749349
< 2.2.6
MEDIUM 6.4 The WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin for WordPress is vulnerable to CSV Injection in versions u… wordfence
← Prev 652 653 654 655 656 657 658 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top