🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 665 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
550ae348-254e-49f5-8046-38629c774802
< 1.3
MEDIUM 6.4 The Scoreboard for HTML5 Games Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'scoreboar… wordfence
54e5989f-3d2c-4ed3-b4c4-f2589b885637
< 3.3.10
MEDIUM 6.4 The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
54e022df-0dc7-4f60-811d-48a92b723d55
< 1.2.2
MEDIUM 6.4 The Osom Blocks – Custom Post Type listing block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
54c90c31-945b-4099-97fe-8c148ded3703
< 5.3.1
MEDIUM 6.4 The WP Plugin Info Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
54ba7d45-475b-41eb-8272-1453eb7f7e03
< 1.3.1
MEDIUM 6.4 The HT Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.0 du… wordfence
54ba2c67-3855-40ce-8880-698bcb2a63f7 MEDIUM 6.4 The Quantities and Units for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
54b662a9-8003-48f6-ace9-fb0d74a05b3b MEDIUM 6.4 The PB MailCrypt plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1… wordfence
54aa406f-0b43-4be9-9c80-aad51f818310 MEDIUM 6.4 The SEO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.1… wordfence
54a610c6-2615-4900-bf63-8ae93aeabb8e
< 1.7.2.9
MEDIUM 6.4 A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the bro… wordfence
549ca9cf-0183-4c19-9bd5-b6d55a69df31
< 4.9.7
MEDIUM 6.4 The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
549acf7a-9e0a-404d-960a-f615ed60cac8
< 12.3.2
MEDIUM 6.4 The TNC FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 12.… wordfence
54998b69-7dc5-49a4-8b8b-3419de73ed47 MEDIUM 6.4 The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alignment’ paramet… wordfence
54970085-5206-45b6-adcf-11e6dd4cd633
< 3.20.2
MEDIUM 6.4 The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the video_html_t… wordfence
5491ff65-9060-4b0b-a31d-7b95ea581310
< 2.6.8
MEDIUM 6.4 The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all vers… wordfence
5490773f-8b04-4a4c-a9aa-3c10c5b2360d
< 3.1.6
MEDIUM 6.4 The Smaily for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.… wordfence
548c3145-eafd-40b0-ada9-eec4406c4169 MEDIUM 6.4 The NV Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6 du… wordfence
547325ad-0b01-42d5-b47c-362044587395
< 5.9.4
MEDIUM 6.4 The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cro… wordfence
546cd218-3f6d-4e8f-83d5-e9aceb6f33ed
< 2.4.30
MEDIUM 6.4 The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(… wordfence
546aee7b-60a6-44bc-8664-0e917974cb6d
< 2.15.8
MEDIUM 6.4 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
545f10df-e473-48df-87ab-87f5e1088e93
< 2.4.9
MEDIUM 6.4 The Responsive Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
545dae6b-7983-4f02-a9a0-0be8cf935a78
< 1.5.17
MEDIUM 6.4 The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s… wordfence
5458e3bf-fd91-4201-8157-572eb1126aaf
< 2.2.5
MEDIUM 6.4 The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom fields in all versions up t… wordfence
544db0d5-1760-4229-8429-d2391e328304
< 1.3.7.6
MEDIUM 6.4 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… wordfence
544d7572-651f-45bb-b2ce-d768553c251a
< 1.1.7
MEDIUM 6.4 The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere … wordfence
543c4d52-0e47-4bbb-b53e-dbe3f104734f
< 5.5.4
MEDIUM 6.4 The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Regi… wordfence
← Prev 662 663 664 665 666 667 668 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top