πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 658 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5b77982e-15ab-4376-89d3-7a2609b118eb
< 5.10.3
MEDIUM 6.4 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for… wordfence
5b74d6aa-ad59-42be-b454-9c27428cab01
< 3.4.1
MEDIUM 6.4 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Imag… wordfence
5b655b04-1f2f-4745-8237-7ef3f8e31ace MEDIUM 6.4 The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in a… wordfence
5b624e9b-d21e-43d2-83ad-7760ed63a75c
< 2.6.9
MEDIUM 6.4 The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
5b494334-6feb-4a10-9636-3f1b1d0d5c66
< 7.5.4
MEDIUM 6.4 The Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.5.3 due t… wordfence
5b33aa60-ac20-42c3-a3ab-b29ddfe2284a
< 3.1.1
MEDIUM 6.4 The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '… wordfence
5b3214a5-7044-4005-a200-c969d4487be2
< 6.6.3
MEDIUM 6.4 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Store… wordfence
5b2e599c-48de-4d3a-94a3-b98badfb7a98 MEDIUM 6.4 The QR Code for WooCommerce order emails, PDF invoices, packing slips plugin for WordPress is vulnerable to Stored Cross… wordfence
5b2bef63-c871-45e4-bb05-12bbba20ca5e
< 6.2
MEDIUM 6.4 The Weaver Xtreme Theme for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of the p… wordfence
5b17e416-7ca5-4447-ad7e-d3da2fddab86
< 1.0.2
MEDIUM 6.4 The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before … wordfence
5b16df88-7d9f-4ee2-90ab-6da50c69148e MEDIUM 6.4 The QR Twitter Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in ve… wordfence
5b15575f-0638-40ec-b152-20ba2225a725
< 2.10.1.2
MEDIUM 6.4 The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
5afb3c3a-17d1-4cfb-9058-ae6a58e04c6b
< 2.4.2
MEDIUM 6.4 The collectchat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.… wordfence
5af467b9-6974-4123-a3e3-67f1fcec01cf MEDIUM 6.4 The Simple-Audioplayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
5ac3ac02-d496-46cb-9aff-ffeeb8fd80fa
< 2.4.8
MEDIUM 6.4 The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all vers… wordfence
5ac1145b-5ab1-47a9-9117-4870c52a70fc
< 2025.0
MEDIUM 6.4 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe'… wordfence
5abf4742-c9db-449c-a814-c9a0abb19efc MEDIUM 6.4 The Photographer Connections plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
5abae31f-2e1b-42c1-a8b0-6847aa853fb4 MEDIUM 6.4 The Infusionsoft Web Form JavaScript plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
5aab3dea-5d14-4316-9a4c-97b0d30762bf MEDIUM 6.4 The Elementor Inline SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all v… wordfence
5a9db562-6810-4da1-9e5f-6f6eadca76ac MEDIUM 6.4 The WP Easy Toggles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggles' shortco… wordfence
5a9c5f98-3457-443c-a87d-64f9c26b4f79
< 3.0.0
MEDIUM 6.4 The "SoundPress Plugin" plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.6… wordfence
5a92916c-42d4-44a6-a9b7-ff0338042b2a
< 0.5.8.2
MEDIUM 6.4 The Off-Canvas Sidebars & Menus (Slidebars) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
5a922aa8-1625-44a9-b283-245e27e6db66 MEDIUM 6.4 The Awesome Fitness Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
5a91e786-f570-4c6c-b1c7-0110774cb808
< 2.3.49
MEDIUM 6.4 The GeoDirectory – WordPress Business Directory Plugin, or Classified Directory plugin for WordPress is vulnerable to … wordfence
5a8f4ec8-d66e-4892-9770-67450aaa83d9
< 2.10.0
MEDIUM 6.4 The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerabl… wordfence
← Prev 655 656 657 658 659 660 661 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top