🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 669 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
51986a76-933b-4c25-af79-d0c3f9e1d513
< 1.3.1
MEDIUM 6.4 The Contact Form Entries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vx-entries' shortcod… wordfence
51889961-e4da-44f3-b422-2c8337278b33
< 1.2.4
MEDIUM 6.4 The 活动链接推广插件 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
51887d22-2cfa-46b8-822c-9e6e183de4ad
< 3.1.4
MEDIUM 6.4 In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) acce… wordfence
51867e4f-75be-4451-a585-87398881adf5 MEDIUM 6.4 The URLYar URL Shortner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'urlyar_short… wordfence
5182843b-03d0-4b0b-ba97-8e9602916c5f
< 1.5.1
MEDIUM 6.4 The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in … wordfence
518174ec-44f5-4b5c-a326-0fb2aa661c86
< 1.7
MEDIUM 6.4 The Formsite | Embed online forms to collect orders, registrations, leads, and surveys plugin for WordPress is vulnerabl… wordfence
515557bf-da71-4076-89bb-ce970ea7befa
< 1.0.75
MEDIUM 6.4 The Earnware Connect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ew_hasrole' sho… wordfence
514a393e-840e-4afb-90fc-a66927624a00 MEDIUM 6.4 The WP ViewSTL plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 d… wordfence
51467cef-9624-4dd9-a368-d3b5fac7bb3d MEDIUM 6.4 The SlideShowPro SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `slideShowProSC` … wordfence
51421320-858a-4d7e-81bb-06fd601ded9e
< 1.0.9
MEDIUM 6.4 The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
513f116b-84d3-4848-b608-f2a2ee57a9a2
< 1.2.0
MEDIUM 6.4 The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Animated … wordfence
51384a40-d239-44a4-b7c7-300f29b83b57
< 1.1.3
MEDIUM 6.4 The Simplebooklet PDF Viewer and Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
51336329-9c4d-45f3-bd16-1b1ef2e68513 MEDIUM 6.4 The Be Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
51296ab5-da96-4461-89f7-9e93f8032b03
< 3.18.4
MEDIUM 6.4 The 12 Step Meeting List plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
5124be64-6679-4dc5-8117-55c73ae91489
< 3.3.3
MEDIUM 6.4 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
51214cd0-23a6-48ba-a3d8-4d9a0a9e52df
< 1.2.7
MEDIUM 6.4 The Appzend theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter i… wordfence
51212d87-8723-4ba7-8fa4-78912a56385f MEDIUM 6.4 The Photospace Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters sav… wordfence
511957c0-e4c3-4a50-b604-3b604d52d32f MEDIUM 6.4 The OWL Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4… wordfence
5113170a-5a53-4e53-84e6-56d9ba0740ed
< 1.3.7.5
MEDIUM 6.4 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LinkWr… wordfence
5106ce6b-70c6-437a-9576-ca537c213a74 MEDIUM 6.4 The Planyo online reservation system plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
50f6d0aa-059d-48d9-873b-6404f288f002 MEDIUM 6.4 The TCD Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'map' shortcode in versions up… wordfence
50f3e469-f788-45da-95e7-aa6da1e87fd1
< 4.3.0
MEDIUM 6.4 The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's urcr_restrict s… wordfence
50eef578-9094-47ac-a451-04ebd9e6e2f8
< 2.49
MEDIUM 6.4 The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-S… wordfence
50e85f2c-3e3a-40b0-af82-7278656533d3 MEDIUM 6.4 The Video Sidebar Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters saved… wordfence
50d8f1e0-2022-4fe1-b384-ca762a032d3c
< 1.9.0
MEDIUM 6.4 The WP Event Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_events' s… wordfence
← Prev 666 667 668 669 670 671 672 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top