🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 659 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5a86958f-b68d-4436-bcc7-d8dc2fc86f47
< 1.3.1
MEDIUM 6.4 The HT Builder – WordPress Theme Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
5a801bb0-a7fc-42c3-b26f-3f7cdb592bea
< 3.2.7
MEDIUM 6.4 The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs… wordfence
5a680db1-3db2-4884-b2fe-c6d29457df4f
< 2.1.0
MEDIUM 6.4 The “Clever Addons for Elementor” WordPress Plugin before 2.1.0 has several widgets that are vulnerable to stored Cr… wordfence
5a64e522-781e-4112-a319-3eea9a4a45d3
< 2.1.7
MEDIUM 6.4 The Enter Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via tags in versions up to, and inclu… wordfence
5a46d9b0-06fa-4bb3-a687-13baeb5fb1f0
< 6.9
MEDIUM 6.4 The Featured Image Thumbnail Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
5a418687-7359-4ebf-8912-2c9f511fe46d MEDIUM 6.4 The Weberino Timed Quiz plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.6… wordfence
5a26367b-e194-42fc-9085-c9d52c416db0
< 1.1.3
MEDIUM 6.4 The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
5a25728c-3d98-414b-bad0-2c05eb1f4ca2 MEDIUM 6.4 The Get Youtube Subs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘channel', 'layout', an… wordfence
5a1d5fd1-80b6-4d62-9837-59ee1e020373
< 5.9.23
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
5a1c6377-c2a7-4344-86bd-d2797db19469
< 2.8.12
MEDIUM 6.4 The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, … wordfence
59f914e2-a671-46cc-a2b8-664816639f3e
< 9.2.01.001
MEDIUM 6.4 The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in… wordfence
59ee0b56-c11f-4951-aac0-8344200e4484
< 1.8.0
MEDIUM 6.4 The WP Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, … wordfence
59ea7390-3587-4fce-b267-bf525dbe3e27 MEDIUM 6.4 Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled ThickBox JavaScrip… wordfence
59e3f965-6f0b-4118-b321-afbd88905719
< 12.9.0
MEDIUM 6.4 The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and excluding, 12.9.0 due t… wordfence
59d9ff2e-4b0b-4096-91ca-1a029f31796b
< 1.1.3
MEDIUM 6.4 The Simplebooklet PDF Viewer and Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
59cdc681-ab73-4701-ba87-e0773242ace7 MEDIUM 6.4 The Events Maker by dFactory plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
59cbc7fc-793b-47b9-80e4-605ac8c2ae86 MEDIUM 6.4 The Icons Enricher plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
59c29b29-fc4d-4ecd-a678-3ddeb39d2baf
< 4.2.6.1
MEDIUM 6.4 The Groundhogg plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.6… wordfence
59bcd246-ca2f-4336-9a6e-89afe873ed25
< 22.7
MEDIUM 6.4 The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ author meta i… wordfence
59bc1c34-15f4-473b-a988-a1c80997e438
< 1.7.92
MEDIUM 6.4 The Simple SEO plugin for WordPress is vulnerable to attribute-based stored Cross-Site Scripting in versions up to, and … wordfence
59b70fce-1327-469e-9df5-3e51c1043a63 MEDIUM 6.4 The Featured product by category name plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
59a349f2-048d-49a5-92ea-c19f1d1cd45e
< 4.1.12
MEDIUM 6.4 The MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution plugin for WordPress is vulnerable to Stor… wordfence
59901afe-b439-4169-bdeb-eb59df890cad
< 2.3.4
MEDIUM 6.4 The Click to Chat – WP Support All-in-One Floating Widget plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
597b48f5-d91f-4427-985e-c1e6e7c57337
< 1.0.6
MEDIUM 6.4 The Info Cards – Gutenberg block for creating Beautiful Cards plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
596e970b-5a40-46cd-aa32-ac6ace39c21b
< 2.1.3
MEDIUM 6.4 The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versi… wordfence
← Prev 656 657 658 659 660 661 662 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top