🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 667 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
536b3d61-d0a3-4613-9a9e-e994806d90f5
< 1.4.20
MEDIUM 6.4 The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
53577cf4-af87-41a2-9424-56a584b78cf3
< 3.2.1
MEDIUM 6.4 The Rating Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in ver… wordfence
53419b7c-e1a5-46ef-9110-c88f43b7df1d MEDIUM 6.4 The SM CountDown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's smcountdown s… wordfence
533f6552-38aa-4251-89fa-e5f79ccb3df0
< 3.1.9
MEDIUM 6.4 The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
532d185c-4384-4b15-a104-42f8d2a1ca23
< 1.0.241
MEDIUM 6.4 The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and in… wordfence
532b58eb-6d8b-4bb7-b5c5-604ad24dba98
< 1.1.42
MEDIUM 6.4 The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin f… wordfence
5324ca6d-37cb-41e4-8355-80ca113f855e
< 1.3.7
MEDIUM 6.4 The Dynamic Widget Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget content fiel… wordfence
531954dd-ed3f-4626-adab-c1bba8407c89
< 3.20.2
MEDIUM 6.4 The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget's custom_… wordfence
530ccf41-f596-4783-b177-36fc9a3a6e81
< 5.9.0
MEDIUM 6.4 The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
52eddb68-7b72-4c47-a365-0676970b5207 MEDIUM 6.4 The Wpresidence Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
52d79cdd-739f-4ae9-9214-bc64ca7d8ecb
< 8.3.7
MEDIUM 6.4 The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget '_id' attr… wordfence
52d4909b-2e21-4067-bee1-e9839fcb7dc8
< 1.3.5
MEDIUM 6.4 The SheetDB plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.4 du… wordfence
52ce7a69-7b65-4150-ad33-1a73ace63d93
< 2.10.45
MEDIUM 6.4 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
52ba91f1-21a2-4d7c-8801-b5e72a00c37d
< 2.4.9
MEDIUM 6.4 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Acco… wordfence
52aee4b8-f494-4eeb-8357-71ce8d5bc656
< 5.0.10
MEDIUM 6.4 The Slimstat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slimstat' shortcode in… wordfence
52a106f6-8d6a-4769-81c0-f8d1bdc72feb
< 4.1.26
MEDIUM 6.4 The PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.25 due… wordfence
52a094b0-acee-412a-ad15-38c9f4510c48
< 1.0.6
MEDIUM 6.4 The Elementor Image Gallery Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
52935b60-3ec5-45e6-9d12-200bf107c9df
< 2.9.4.3
MEDIUM 6.4 The Uncode Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uncode_hl_text' and … wordfence
528e1227-e6f5-4676-ad99-93259fd334de MEDIUM 6.4 The WP AdCenter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.… wordfence
5287cf42-6d0a-4fd2-943d-e8e44fc08576
< 5.1.1
MEDIUM 6.4 The Jetpack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a shortcode in versions up to, and inc… wordfence
5284cbe4-1550-4f3c-be54-e2de8a089512
< 2.5.1
MEDIUM 6.4 The Big Boom Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bbd-search' s… wordfence
527f75f1-6361-4e16-8ae4-d38ca4589811 MEDIUM 6.4 The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Server Side Request Forgery via the 'crayon' shortco… wordfence
527dd2c7-5bbb-4c79-aa3c-7d70ddd26163
< 1.2.4
MEDIUM 6.4 The Breeze Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cal_size’ parameter in… wordfence
526c45c8-7543-4384-af80-b3798857f79d
< 2.1.0
MEDIUM 6.4 The Edge theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.9 due to… wordfence
52659f1c-642e-4c88-b3d0-d5c5a206b11c
< 3.0
MEDIUM 6.4 The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpsscode' sho… wordfence
← Prev 664 665 666 667 668 669 670 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top