🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 662 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
57103f8e-0874-4e56-8571-254607ada21c MEDIUM 6.4 The Swift Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortc… wordfence
56fdbf80-8ea2-412a-b166-b7c27de88e70
< 4.4.6
MEDIUM 6.4 The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_su… wordfence
56fd8166-da22-4a0b-a23f-41817acba6df MEDIUM 6.4 The R Animated Icon Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all… wordfence
56fab3af-370d-4dba-bf21-775dabc7823d MEDIUM 6.4 The Lightweight and Responsive Youtube Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
56fa7885-dc36-420b-a6cc-4fc2192112eb MEDIUM 6.4 The wp custom countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
56f3aa7a-a6f2-42c7-b855-b083fe58f466 MEDIUM 6.4 The Custom Frames plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter of the 'cu… wordfence
56ec086e-01a7-42f8-be17-b2bdf59cdfb8 MEDIUM 6.4 The React Webcam plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in vers… wordfence
56e842c8-61ac-4281-8c4a-9cb1f8ecc062
< 2.3
MEDIUM 6.4 The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
56e60322-2934-4074-a484-854ba2c53a54 MEDIUM 6.4 The Hypotext plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.1 d… wordfence
56e5f7c9-ad22-43b3-9bfe-0eea1f8040d3
< 1.9.1
MEDIUM 6.4 The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘position’ parameter in… wordfence
56dc5138-c864-4e36-8b7d-38ac49589c06
< 7.1.8
MEDIUM 6.4 The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode… wordfence
56d8af3b-6c00-49ed-872a-64f7bebb470b MEDIUM 6.4 The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]'… wordfence
56d1d152-946f-47c9-b0d5-76513370677f
< 3.1.7
MEDIUM 6.4 The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
56c1a28e-c37b-431d-bb0d-7d9cf4f85606
< 1.0.11
MEDIUM 6.4 Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin before 1.0.11 for WordPress allow remote a… wordfence
56be227d-1273-4833-a94e-67abf89f00ba
< 1.9.9
MEDIUM 6.4 The Apollo13 Framework Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a13_alt_l… wordfence
56ba7d1b-7afd-4069-8b18-1158911fce3f
< 6.5.4
MEDIUM 6.4 The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
56b637dc-4382-438f-ae36-e5075580a7d6 MEDIUM 6.4 The Useful Tab Block – Responsive & AMP-Compatible plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
56b4d715-7ec4-4d5b-ae2c-ec19310e72ab MEDIUM 6.4 The Tigris Flexplatform plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
56ac720a-db1e-4aca-b12c-5289fa7b8b9e
< 2.1.9
MEDIUM 6.4 The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Galle… wordfence
56a7d55a-e581-4e36-b795-084e26f3e766 MEDIUM 6.4 The Kiwi plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.8 due t… wordfence
569f2250-971a-4000-9114-67e609ec907d MEDIUM 6.4 The Tithe.ly Giving Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode … wordfence
569d6496-0ad5-4e09-9f3d-b8d3a3121cdf
< 2.8.19
MEDIUM 6.4 The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
569816e6-c561-4de1-a5bc-3d020aab88ee MEDIUM 6.4 The Maps – Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and in… wordfence
568faf41-72ac-4334-a960-a2ce790407ff
< 1.1.0
MEDIUM 6.4 The WooCommerce Cart Count Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions u… wordfence
5684d4b7-8a3e-47ee-9d7b-195cb5db9a66 MEDIUM 6.4 The WP Catalogue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all … wordfence
← Prev 659 660 661 662 663 664 665 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top