πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 657 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5c30aff0-f8ee-408b-a144-0a8d12beda4c
< 2.8.19
MEDIUM 6.4 The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
5c2988e9-85c2-44ab-847d-014206774824
< 2.0.12
MEDIUM 6.4 The Futurio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
5c275b40-1155-4a86-8854-b0660e117fcb
< 2.2.3
MEDIUM 6.4 The Simple Staff List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in… wordfence
5c0963b2-210b-4dca-96a8-d048e4c53b5b MEDIUM 6.4 The Mime Types Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versio… wordfence
5bfe0a05-6bf9-4acc-bf9d-05079c3b3664
< 3.11.3
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's PDF Vi… wordfence
5bfc718a-408b-4389-b03b-bfe152ed7b28
< 7.4.9
MEDIUM 6.4 The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
5bf50fe7-ca09-45ee-bd25-057e0a7f6dd2 MEDIUM 6.4 The Soledad theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.7.2 due… wordfence
5bf12608-4e02-4b3a-9363-991dca5ee11b MEDIUM 6.4 The Client Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aft_testimonial… wordfence
5bedca60-cf63-4954-a880-7a9e4dc267c2 MEDIUM 6.4 The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPres… wordfence
5bea454e-bd1a-4cdf-acec-7bf15f6a6cda
< 2.0.32
MEDIUM 6.4 The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
5be80212-dfbf-4e89-b1f6-44489c2f5048
< 1.5.3
MEDIUM 6.4 The Advanced FAQ Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
5be80195-192a-4b53-9d10-4d877fa0afbe MEDIUM 6.4 The WordPress Ajax Load More and Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
5bd03cd0-34f0-491c-8247-79656eba32a8
< 2.3.3
MEDIUM 6.4 The Favorites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_favorites' shortcode in ve… wordfence
5bc6d354-65f5-4c1e-8a43-a6ddd1280a2f
< 4.0.4
MEDIUM 6.4 The MainWP Rocket Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and including,… wordfence
5bc03b4a-f7ec-4827-b914-0560b9268b6f
< 3.8.5
MEDIUM 6.4 The Front User Submit | Front Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field labels … wordfence
5bbccacf-0c34-4656-834b-b3b4c0a84abe MEDIUM 6.4 The Slideshow, Image Slider by 2J plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
5b9e92ea-49fc-420d-9d0e-29bcf78843bd
< 1.2.8
MEDIUM 6.4 The Affiliate Program Suite β€” SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
5b9d61cd-1955-40d0-99b4-c75f480733f8
< 1.3
MEDIUM 6.4 The FireCask Like & Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' param… wordfence
5b974e9e-9897-400c-b145-dc8a2d54b553 MEDIUM 6.4 The Art Decoration Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod… wordfence
5b8e052a-6e60-4455-96c9-b2a3e86773da
< 3.1.1
MEDIUM 6.4 The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPre… wordfence
5b839658-c472-40f0-855f-7201baeb790f
< 3.5.22
MEDIUM 6.4 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's U… wordfence
5b80fc93-212e-481d-907c-275139782e77
< 1.3.2
MEDIUM 6.4 The Confetti Fall Animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'confetti… wordfence
5b7f3f0f-5f02-41d7-ac37-ecdde74fc532
< 2.7.0
MEDIUM 6.4 The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plug… wordfence
5b7e4c3c-a12e-4b11-9673-79a7060052a8
< 4.3.9
MEDIUM 6.4 The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'betterdocs_feedback_form' shor… wordfence
5b792892-25dc-4df0-883d-afd0b47292e0 MEDIUM 6.4 The Flickr Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'div_height' parameter of the … wordfence
← Prev 654 655 656 657 658 659 660 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top