🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 663 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5684366b-f09c-4710-a43e-ff451d88b0e1 MEDIUM 6.4 The User Login Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘column_name’ parameter… wordfence
56822fe5-352c-4269-9fab-d8c796362b74
< 6.13.2.1
MEDIUM 6.4 The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ para… wordfence
56730afc-aa1e-4e97-b74e-9b5d3f78c677 MEDIUM 6.4 The Reactive Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
566f19d0-f0b6-47f4-b09a-3c9613ea8057 MEDIUM 6.4 The Daily Proverb plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
566be246-1722-44c0-aa18-bcf9d2a7ddc6 MEDIUM 6.4 The Quick Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' attribute of the 'qtbl… wordfence
5666e2b7-acb3-4abb-ac2a-1575206435cf
< 1.7.1013
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Woo G… wordfence
5666da4a-ffb6-47ed-8b48-a80f09dd2501
< 3.7.1
MEDIUM 6.4 The Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) plugin f… wordfence
5659af1d-f248-46ff-b282-ef5397222d8d
< 1.1.8
MEDIUM 6.4 The AI BotKit – AI Chatbot & Live Support for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
5658c9a8-55a0-4e18-8231-e3c5dfb01be4
< 1.3.6
MEDIUM 6.4 The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
5653f1aa-06da-4208-afa2-19ef31b8be2f
< 6.0.10
MEDIUM 6.4 The Google Language Translator plugin for WordPress is vulnerable to Cross-Site Scripting via the glt shortcode in versi… wordfence
5652587e-280b-4bdf-b096-e09fe0194658
< 1.0.8
MEDIUM 6.4 The Woo Products Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'… wordfence
5648fc33-3284-4f71-bc2b-6e72237b2ca1
< 6.1.3
MEDIUM 6.4 The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
563f559e-528a-4d6b-98be-a3c2f45fee53
< 1.5.0
MEDIUM 6.4 The Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO – Media Library Tools plugin for Wo… wordfence
563d44cd-5f5a-4914-8312-c554085b0821
< 2.8.8
MEDIUM 6.4 The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor… wordfence
56399c7b-7bf7-455a-8e11-77b4e3e104a3 MEDIUM 6.4 The Fancy User List plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
562f194f-1f32-4de4-8074-84580f653bdb
< 1.0.5
MEDIUM 6.4 The Any Post Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aps_slider shortc… wordfence
5618fdfc-636f-452b-80e1-5182b068d1c6
< 2.7.20
MEDIUM 6.4 The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to DOM-Ba… wordfence
56104b40-2d8a-40c9-8e80-01a093e54424
< 2.9.5.1
MEDIUM 6.4 The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.5… wordfence
5607a60e-a04a-4d28-bb04-bdacf8e97c56
< 2.2.4
MEDIUM 6.4 The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2… wordfence
5607882d-9112-45f9-bee0-a0c077419187
< 3.0.2
MEDIUM 6.4 XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gist… wordfence
55ff923e-9d04-4ce7-b6d6-165fa4fc5433
< 1.1.4
MEDIUM 6.4 The Cards for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Cards wi… wordfence
55fd9ca6-fe57-490d-bfde-492957035311
< 3.6.0
MEDIUM 6.4 The WP Travel Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
55fd13aa-aa30-4d5b-b344-6b5d065b64ce MEDIUM 6.4 The Simple Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in … wordfence
55eeeb28-262e-49c5-a2b3-944345a9142d
< 1.2.6
MEDIUM 6.4 The Esotera theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.5.1 d… wordfence
55e6eb58-79e2-4404-887a-0392ce7914aa
< 2.2.81
MEDIUM 6.4 The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordP… wordfence
← Prev 660 661 662 663 664 665 666 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top