πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 661 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5852f08d-0506-464e-afd1-c625e4034e1d
< 2.5.11
MEDIUM 6.4 The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u… wordfence
58354ce0-e166-431a-9fac-6c6d81e39e88 MEDIUM 6.4 The Enable SVG Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG files in versions up to… wordfence
57ef5302-3cf3-4253-8b25-54c09ad872ed
< 1.6
MEDIUM 6.4 The WP About Author plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
57ed6c7e-ca8d-476d-adce-905b2cd2eda8
< 5.9.20
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
57e9b09c-adfb-4fc2-8d2b-41cfc1f73e22
< 3.0.2
MEDIUM 6.4 The Zoho Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all ve… wordfence
57e6c1e1-efc4-4fef-b6c0-7657d21d61a4 MEDIUM 6.4 The Countdown Timer for WordPress Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
57dac6de-545f-49e5-9f45-d90a48d6b05f
< 2.4.41
MEDIUM 6.4 The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the embedded media cust… wordfence
57d9b98d-34c3-4bbf-af9a-e93835857e2d MEDIUM 6.4 The Unlimited Addon For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
57cef1ed-f225-41b6-8cd2-d40175a48838
< 1.0.4
MEDIUM 6.4 The Official SalesWizard CRM Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
57c14da1-b57c-4425-bacc-f864d237ce10
< 1.4.1
MEDIUM 6.4 The Sinatra theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4 due t… wordfence
57bf222b-5f49-46e2-be84-3e6444807096
< 1.3.977
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜cu… wordfence
57becd55-808e-49e6-93f3-2e380c494c5f
< 1.3.9
MEDIUM 6.4 The WP Posts Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
57be3e10-6920-4ad8-b9cf-cf5a703ca373
< 1.7.0
MEDIUM 6.4 The Widgets on Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in ve… wordfence
57bbc2f3-8d31-4e73-a7f8-569109311b94 MEDIUM 6.4 The Churel theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.8 due … wordfence
57b7b171-cd25-4bcd-aa75-3ccbfbb1452a
< 12.8.6
MEDIUM 6.4 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
57aea77c-fa81-4c5a-ade1-cc2eb511fcb2 MEDIUM 6.4 The Direct Checkout Button for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… wordfence
57865837-470e-4afd-bb90-d203a78a210b MEDIUM 6.4 The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing… wordfence
5782c338-1474-48e1-8b1d-015e3bb1c23d
< 1.3.5
MEDIUM 6.4 The Themify Event Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
576aba7a-9f8c-4c03-8310-7edd29bf0d2a MEDIUM 6.4 The Library Bookshelves plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
57666105-81e4-4ef4-8889-9ce9995d2629
< 3.7.8
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, … wordfence
57641366-85d3-4375-8cde-041227c9f811
< 1.9
MEDIUM 6.4 The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dd-parallax shortc… wordfence
575f103e-cfc7-4efd-a592-658a3e919671
< 1.13.4
MEDIUM 6.4 The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cro… wordfence
574dd6d8-14df-47b8-bf03-28a3c02b73ec
< 1.0.14
MEDIUM 6.4 The BookingPress – Appointments Booking Calendar Plugin and Online Scheduling Plugin for WordPress is vulnerable to SQ… wordfence
573c07f0-1ce5-456d-9094-47cb7d8ba9f0
< 2.0.14
MEDIUM 6.4 The PropertyHive plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,… wordfence
572b584e-b580-4d90-88b6-ee5b25678d9b MEDIUM 6.4 The WP Restaurant Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter o… wordfence
← Prev 658 659 660 661 662 663 664 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top