🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 664 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
55d842fc-a750-4b59-a1d6-b3bd427dfe79
< 1.8.6
MEDIUM 6.4 The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortc… wordfence
55cd02d1-7b06-427b-840b-3ced73ad4a74
< 1.8
MEDIUM 6.4 The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in al… wordfence
55c631c6-4e7c-488c-968d-2e1afd11a75d MEDIUM 6.4 The OpenCart Product Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
55c5c094-69c0-4e2a-be0c-fab6f1039309
< 5.3.1
MEDIUM 6.4 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross… wordfence
55b39859-b8a0-418b-ae7a-cd42d6e0bf00
< 2.1.10
MEDIUM 6.4 The Mail Subscribe List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘smlsubform’ short… wordfence
55ae710e-469e-4b36-b443-39228ad2a584
< 2.0.19
MEDIUM 6.4 The Post Grid Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
55a64d00-a750-47b0-bc0b-95ad043ccb85 MEDIUM 6.4 The Easy Shortcode Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
55981e72-8d1a-4075-a372-6bddc95e99d8
< 5.6.3
MEDIUM 6.4 The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordP… wordfence
5596197e-149d-4072-9fa4-424c9ffd6059
< 1.4.3.1
MEDIUM 6.4 The 140+ Widgets | Best Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
559165ed-f7f6-4f5a-ad37-8a2d53924888 MEDIUM 6.4 The Best Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
558e36f6-4678-46a2-8154-42770fbb5574
< 7.0.0
MEDIUM 6.4 The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
558679ea-a8ee-4329-8ad7-34b708476b53
< 7.13.53
MEDIUM 6.4 The Super Socializer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in … wordfence
55838de5-0795-429b-be87-a0d57b29e471 MEDIUM 6.4 The Image Magnify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'image_magnify' sho… wordfence
557bdd07-c846-41f1-b780-52537f47b15a
< 2.8.3
MEDIUM 6.4 The Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
55797931-e2eb-4cd7-8de6-ded7e1a382a0
< 1.7
MEDIUM 6.4 The Sitekit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versi… wordfence
556e41d1-2c98-4175-87ba-29689704c2f0
< 4.0.6
MEDIUM 6.4 The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field in all ve… wordfence
5569e2fa-ce20-4ad0-8089-7c9ec792cc44
< 1.4.25
MEDIUM 6.4 The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
5545aab7-da77-4404-90e8-7b3e413769b5
< 3.0.7
MEDIUM 6.4 The Location Weather plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
55430010-f18f-4d8d-bbfa-cc02344369e0 MEDIUM 6.4 The ABC Notation plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.1… wordfence
5538f3e6-b17f-4dd0-aa5a-d190c128d977
< 1.2.9
MEDIUM 6.4 The HT Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's in all versions up to, an… wordfence
552c0810-9687-4a66-91a4-e34228552a15
< 1.5.8
MEDIUM 6.4 The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
552a5d94-8727-4840-8be1-ab165ddf4eae
< 6.1
MEDIUM 6.4 The Gallery with thumbnail slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
55203d91-ae6b-4ec0-8bbe-be7f65b4f34b MEDIUM 6.4 The Ultimate Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
551d4ad8-9074-45dc-9404-3cbee9fdcd44 MEDIUM 6.4 The Tabbed Login Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
550ae92f-6250-4cbd-85d0-a9054aee3916
< 4.4.0
MEDIUM 6.4 The WP Live Chat Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wplc_update_admin_… wordfence
← Prev 661 662 663 664 665 666 667 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top