🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 660 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
596d3b55-e35b-4d77-9915-1091eafbb3ff MEDIUM 6.4 The Mutual Funds Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attrib… wordfence
596ccda4-1baf-4391-a894-9312e2c06767 MEDIUM 6.4 The mFolio Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.… wordfence
5947596b-12c6-492c-bebe-a935a24f4c3e MEDIUM 6.4 The Links/Problem Reporter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
593fefe1-8813-440b-b8c7-fbfd5b71a737 MEDIUM 6.4 The WPGancio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gancio-event' shortcode… wordfence
593202db-9900-4ffc-9062-24f1906c1a57
< 8.5.15
MEDIUM 6.4 The WP VR plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.5.14 due… wordfence
592b1df5-74d5-4414-aacb-7497f0f307f1
< 1.7.0
MEDIUM 6.4 The Digital Publications by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via all of the i… wordfence
59256cf6-76a0-44fe-84fb-8873884e71ac MEDIUM 6.4 The SimpleGMaps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 … wordfence
5921b859-79de-48f9-a664-f2bc3ccec201
< 8.6.7
MEDIUM 6.4 The MapSVG Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.6.… wordfence
591ddcd7-9ed1-47b5-89c5-fd477bc9f9a9
< 1.4.5
MEDIUM 6.4 The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
590bdf82-8006-4729-96e5-42b0d1552d19 MEDIUM 6.4 The Cool YT Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'videoid' parameter in all … wordfence
58fe6f67-1139-4d3e-864d-3966cede5077
< 1.20.5
MEDIUM 6.4 The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popupID' parameter in all v… wordfence
58fcab5e-c82e-4072-9a86-94a7f18a6e56
< 6.3.11
MEDIUM 6.4 The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordP… wordfence
58f86bdb-2332-4972-bf00-f7370ffd0c57
< 3.4.1.2
MEDIUM 6.4 The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Quiz values in all versions up to, a… wordfence
58f4bd87-0050-4b61-842d-52d037840bb0
< 2.1.00
MEDIUM 6.4 The MarketKing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.9… wordfence
58e9c535-1b36-4795-b8f6-b38f3fc3d164
< 2.0.1
MEDIUM 6.4 The Surbma | Recent Comments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'… wordfence
58dfd766-7156-4aec-b8db-76908b775ba0
< 8.4.2
MEDIUM 6.4 The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Marq… wordfence
58ae3a89-200b-475c-8d32-a24502eb95c6
< 1.6.0
MEDIUM 6.4 The Annual Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in vers… wordfence
589f5456-1d72-4eac-bd9b-2bedf4109daa
< 3.0.0
MEDIUM 6.4 The NotificationX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
588e12c4-7d68-40ac-82bc-aacc5d389dee
< 3.1.7
MEDIUM 6.4 The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text… wordfence
58884dcb-dad3-4856-aa54-c5b769d4f9e1
< 6.2.8
MEDIUM 6.4 The Use Any Font | Custom Font Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several pa… wordfence
58854b23-e679-4349-aa7c-4edf4008c92a
< 1.3.9
MEDIUM 6.4 The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Cust… wordfence
5873ad24-a105-4ad0-b809-5bf13e61b0fa
< 4.9.14
MEDIUM 6.4 The Spiffy Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
5862dcc6-8daf-4046-9dff-d87cf3b3f83e MEDIUM 6.4 The Advanced Control Manager for WordPress by ItalyStrap plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
5860fe2a-edb4-4542-9a87-d0ab6819dd77
< 1.0.94
MEDIUM 6.4 The EventCalendar plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.0.94 due to insufficie… wordfence
5860d456-a992-4816-8c93-7311c33734e4
< 2.3.11
MEDIUM 6.4 The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Gutenberg blocks in versio… wordfence
← Prev 657 658 659 660 661 662 663 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top