🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 656 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5d128197-802c-48fb-8782-eb4e10126e55 MEDIUM 6.4 The WP Tiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions… wordfence
5d03c798-dc77-407c-8674-d0bd2f1ada8c
< 2.23
MEDIUM 6.4 The Pure Chat – Live Chat Plugin & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pur… wordfence
5ce70e87-6dee-4d4a-b2fc-93fd4d50957d
< 4.0.1
MEDIUM 6.4 The hCaptcha for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf7-hcaptc… wordfence
5cdd64a4-040b-4dc9-a8df-dbecfeb928c8
< 3.2.86
MEDIUM 6.4 The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s)… wordfence
5ccece54-18fa-42e4-ba1a-d0879b73d66d
< 1.3.987
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ur… wordfence
5cccd266-48a8-481e-8fbd-db5a9a72f55a MEDIUM 6.4 The Cosmic Blocks (40+) Content Editor Blocks Collection plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
5cbd6040-0446-41fe-8fef-c9065beeaa3a
< 7.6
MEDIUM 6.4 The ND Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's upload feature in a… wordfence
5cbcb659-6732-4893-b6a0-52a558cea351
< 1.3.9.4
MEDIUM 6.4 The WOOCS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and includi… wordfence
5cbb7db4-bef7-4799-9b65-ebe77976e21c
< 7.4.6
MEDIUM 6.4 The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in al… wordfence
5cbb28e2-a7a1-4e33-93e5-872d6f2e00ec
< 2.0.0
MEDIUM 6.4 The XX2WP Integration Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mxp_fb2wp_display… wordfence
5cb5368f-99b1-43e3-a2e4-67e90c8edfcf
< 2.02
MEDIUM 6.4 The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' parameter in … wordfence
5caa9c7c-07b3-4288-803f-f60e5b428953
< 1.4.8
MEDIUM 6.4 The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cros… wordfence
5c8a4708-eb74-45e1-ba47-e245491a8c2f
< 1.8.3
MEDIUM 6.4 The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extractMessage’ and '… wordfence
5c7ed7c5-1a6d-41aa-a13c-c95b14573de8
< 1.7
MEDIUM 6.4 The Woobox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6 due t… wordfence
5c7b9827-59a7-4a8f-88d5-0b27c3ea2925
< 1.1.1
MEDIUM 6.4 The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'portfolio_name' parameter in… wordfence
5c7973be-cf39-4452-9e41-19d2e6aa5e97
< 1.9.6
MEDIUM 6.4 The Gutenberg Blocks and Page Layouts – Attire Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
5c6a6422-8255-4a3c-9ddf-b5986e1d393f
< 4.1.0
MEDIUM 6.4 The WP jQuery DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_jdt' shor… wordfence
5c5822b9-7fd0-4c39-a298-70d0debcc136
< 1.5.3
MEDIUM 6.4 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dat… wordfence
5c50b451-519c-4da8-93ce-b84e594e6775
< 6.9.16
MEDIUM 6.4 The Advanced Access Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter i… wordfence
5c4e8106-6e0b-4b0b-a693-f30bfe87ff92 MEDIUM 6.4 The Booking.com Banner Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
5c4d28e3-60b6-4014-a226-7bd474ad4c46 MEDIUM 6.4 The SS Font Awesome Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
5c482b6e-ce1e-46e2-8847-10c485594448
< 8.1.14
MEDIUM 6.4 The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to Sto… wordfence
5c440ae0-311d-4d0a-a216-7641c2a80669 MEDIUM 6.4 The App Landing Template Blocks for WPBakery (Visual Composer) Page Builder plugin for WordPress is vulnerable to Stored… wordfence
5c43c6f7-afc5-4b7a-96cc-cebfd875a47b
< 1.5.3
MEDIUM 6.4 The Waymark plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5.… wordfence
5c38f080-59c7-4201-9e87-87ee9ab6b97b
< 1.0.4
MEDIUM 6.4 The InteractiveCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… wordfence
← Prev 653 654 655 656 657 658 659 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top