πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 666 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
54396942-551f-49e2-9ee7-40b760e6f0a2
< 1.2.9.1
MEDIUM 6.4 The AffiliateX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.9… wordfence
5438a03c-9081-4e1a-ad81-2e7a0f180e84
< 1.4.0
MEDIUM 6.4 The WP Mail SMTP by WPForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tab parameter in v… wordfence
5437d812-c08f-4465-841e-47dbdf61b5cf
< 1.2.12
MEDIUM 6.4 The Hive Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2… wordfence
543507a1-02de-417f-a742-7764465987b2 MEDIUM 6.4 The Bamazoo – Button Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dgs … wordfence
54255e66-2bc0-4ec4-b482-c27675a84ca1 MEDIUM 6.4 The Hoo Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
541cb2b1-1657-4f26-932f-c32bd51ad970 MEDIUM 6.4 The Alert Me! plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.4.0 … wordfence
5411725e-b670-4097-8517-1092935a7b22 MEDIUM 6.4 The Magic Embeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1… wordfence
540b1b4e-474d-48a8-ac8c-b7cd589ddc4c MEDIUM 6.4 The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
54087ddd-5c13-40ff-be80-3d713603f566
< 5.0.6
MEDIUM 6.4 The Dokan Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.5 … wordfence
54044fd7-facf-4ac2-8c87-e30db78eba40
< 2.7.8.4
MEDIUM 6.4 The Travel Booking WordPress Theme for WordPress is vulnerable to both Reflected and Stored Cross-Site Scripting via sev… wordfence
5402c009-f3c0-4286-9162-6e60322c5544
< 1.9.7
MEDIUM 6.4 The GS Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in ve… wordfence
53fc946c-285a-4d48-8430-777e94df07c5
< 1.8.4
MEDIUM 6.4 The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid p… wordfence
53e16bca-7c85-4d56-8233-b3b53f793b39
< 4.15.1
MEDIUM 6.4 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
53d65d4c-4bd6-4e18-b7ba-ee64328faf32
< 2.4.6
MEDIUM 6.4 The Wilmer Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and … wordfence
53c59793-27db-44fa-92c8-2184d6914d8f MEDIUM 6.4 The CSV to SortTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csv' shortcode in all ve… wordfence
53b24f9a-f225-40b5-9937-f7449d4832df MEDIUM 6.4 The Responsive FlipBook Plugin Wordpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the rfbwp… wordfence
53ad0496-a484-48e4-aa17-29d63e1a47e1 MEDIUM 6.4 The Elementor AI Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
53a51408-e5d8-4727-9dec-8321c062c31e
< 9.1.1
MEDIUM 6.4 The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-recipe-text… wordfence
539b8433-e896-4e4d-a536-cfe055bb91e4
< 3.2.8.6.1
MEDIUM 6.4 The RestroPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.… wordfence
538b4d4b-f8c6-44db-89d2-d345bfbfecb2
< 2.2.0
MEDIUM 6.4 The List Children plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'list_children' sho… wordfence
53880f49-a2f0-4864-ba85-8fbf06ea7833 MEDIUM 6.4 The Custom links in Elementor Image Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
538172a3-a153-4f44-87f5-be4008552e6b MEDIUM 6.4 The Twitter Bootstrap Collapse aka Accordian Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
537594d6-9412-4ff1-bf14-bc1164e5358d
< 4.1.1
MEDIUM 6.4 The Compact Archives plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
53706deb-d49c-4397-98f9-dc37f1d35031 MEDIUM 6.4 The Frontend File Manager Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
53704fa2-9607-4e5c-8249-699a4db1a2c0
< 3.6.4
MEDIUM 6.4 The JetSmartFilters plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
← Prev 663 664 665 666 667 668 669 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top