πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 668 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5263349f-e85f-4d36-a949-d68d31a02e0e MEDIUM 6.4 The Drivr Lite – Google Drive Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions… wordfence
525dec5b-b457-483c-ab2d-09dd320edcaa
< 8.2.0
MEDIUM 6.4 The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a featured image 'alt' attribute i… wordfence
525d2bc5-b0f5-46d9-bb05-1ed0bf640af9 MEDIUM 6.4 The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
52569aac-1e9e-40fb-9ff4-5eeb7940375d
< 2.0.0
MEDIUM 6.4 The CodeMirror Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Code Mirror block in all… wordfence
5246efbb-93cc-4951-900e-d13d08840f03
< 2.7.7
MEDIUM 6.4 The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,… wordfence
52417477-7318-4d7d-8143-765c843abc31
< 2.0.4
MEDIUM 6.4 The Themify Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
523e80a5-dffa-4eb6-8f7a-e179e0dc4d28 MEDIUM 6.4 The Inline Google Spreadsheet Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's … wordfence
5239c414-cd1d-4257-9f8e-e7a92c2119f9 MEDIUM 6.4 The Pricing Table by PickPlugins plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button Link i… wordfence
52368b7d-5fe2-444c-bd7f-e4385dffa8a9 MEDIUM 6.4 The Niche Hero | Beautifully-designed blocks in seconds plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
5235a235-911e-4462-90c5-05b0c7cb45a3 MEDIUM 6.4 The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in t… wordfence
521bb5a3-0a0c-4693-a87d-fabb64f1ad4f
< 1.6.149
MEDIUM 6.4 The Mesmerize Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mesmerize_co… wordfence
52144ff6-0617-496c-8159-ec5d7bc86f60 MEDIUM 6.4 The Marketing and SEO Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in … wordfence
52116a6f-506f-4eeb-9bcc-19900ef38101
< 2.29.7
MEDIUM 6.4 The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the legacy Image wi… wordfence
5208529c-4ac3-42a4-82d0-7f4d2e486236
< 2.0.46
MEDIUM 6.4 The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG uploads in versions up t… wordfence
520555b4-35e8-4ec1-85b8-3a43b5209661
< 1.2.6
MEDIUM 6.4 The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
5201963b-3b30-4e7a-9ad1-d9fa7bf629e5
< 4.5.5
MEDIUM 6.4 The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in vers… wordfence
51f3497f-c599-4d47-bd5a-94e1679a0025
< 3.2.31
MEDIUM 6.4 The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's forgot-password s… wordfence
51eb2e13-3f4e-4b27-bc71-85d4eced3cde MEDIUM 6.4 The ReverbNation Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
51e1bf48-a801-4eec-aebd-f4824f36a623
< 1.3.5
MEDIUM 6.4 The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
51d3d738-5c82-4f6b-b8f3-d5af5391b6f6
< 2.7.9.5
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown W… wordfence
51cc6247-1948-4de1-b347-c7d818400777 MEDIUM 6.4 The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to Stored … wordfence
51ca3ed9-6c3e-44c6-b746-8415e27abed0
< 4.10.0
MEDIUM 6.4 The Post Expirator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4… wordfence
51aa0d86-e623-46d1-9d37-a36b4825c071
< 1.0.27
MEDIUM 6.4 The Investi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'investi-announcements-accordion' … wordfence
51a49b5b-c0a3-4aac-84cc-6e1ebf3a442e
< 6.9
MEDIUM 6.4 The Content text slider on post WordPress plugin before 6.9 does not sanitise and escape the Title and Message/Content s… wordfence
51a4886b-2e15-4d91-b853-4a675120a9e9
< 2.0.0
MEDIUM 6.4 The Ultimate Store Kit Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
← Prev 665 666 667 668 669 670 671 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top