🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 670 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
50cb130d-2e9c-429c-a56c-4546e705981a
< 1.0.3
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in the Plotly plugin before 1.0.3 for WordPress allows remote authenticated use… wordfence
50c8a20a-66b4-445e-9167-e6fc0e6a1000
< 1.4.17
MEDIUM 6.4 The BuddyForms Moderation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buddyforms_moderato… wordfence
50bfbde2-2ccc-483a-95f5-a2ad284fda23
< 1.3.8
MEDIUM 6.4 The Dynamic AJAX Product Filters for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
50b4e000-3fd3-4c5e-abd7-543f933d3cf7 MEDIUM 6.4 The RAphicon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.2 d… wordfence
50b080aa-b9fe-48ac-922c-3f702fed1066 MEDIUM 6.4 The Pop-Up Chop Chop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘email_data’ paramete… wordfence
509a24ef-160a-4e54-bd83-ac1704a32766
< 1.10
MEDIUM 6.4 The Boot-Modal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.1… wordfence
508e97a0-9757-426c-bf0f-cdce6b489ce7
< 7.7.0
MEDIUM 6.4 The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all vers… wordfence
5080c13a-19f9-4260-abba-1c579a6d305b
< 1.5.10
MEDIUM 6.4 The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ver… wordfence
507bc365-b47d-4011-b554-ceab71a9d31d
< 4.0.4
MEDIUM 6.4 The Showpass WordPress Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
50721265-dbbf-4032-a8d6-9cf42a986c0d
< 1.1.7
MEDIUM 6.4 The WIP WooCarousel Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wip_woocaro… wordfence
50631f6c-de8b-408e-ab1f-ef74d3180e7f MEDIUM 6.4 The Toolbar Extras for Elementor & More – WordPress Admin Bar Enhanced plugin for WordPress is vulnerable to Stored Cr… wordfence
5050454a-d705-4af6-a1a3-cde00e72cf35
< 1.3.8
MEDIUM 6.4 The WP Posts Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
503dcefe-1147-4b8e-96e2-c21f49a7bc5b
< 4.19.3
MEDIUM 6.4 The Word Balloon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in version… wordfence
5039d63b-377d-435a-be31-4ae81ea30dd3
< 1.42.1
MEDIUM 6.4 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored C… wordfence
5035d412-861a-4a31-b5e5-378fc4962d90 MEDIUM 6.4 The MyQtip – easy qTip2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `myqtip` sh… wordfence
50283a4f-ea59-488a-bab0-dd6bc5718556
< 1.4.3
MEDIUM 6.4 The Bellows Accordion Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions … wordfence
500fd8aa-9ad1-41ee-bbeb-cda9c80c4fcb
< 1.15.3
MEDIUM 6.4 The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Ready Function’ field in … wordfence
500d2a59-c017-460a-bf25-c9e75b458da6 MEDIUM 6.4 The Carousel Horizontal Posts Content Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
5000c86b-b535-48de-b3e0-0dd0d2fd9b1e
< 3.1.1
MEDIUM 6.4 The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is v… wordfence
4ffd76a2-6700-4c2a-858d-4c7339a8d09a
< 1.1.12
MEDIUM 6.4 The Videojs HTML5 Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's videojs_vide… wordfence
4feed0da-f5b1-47eb-9454-8539f62335fa
< 3.1.4
MEDIUM 6.4 In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accept… wordfence
4feaad82-f94e-49f5-8e8b-67ba220b1c71
< 2.0.0
MEDIUM 6.4 The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderCol… wordfence
4fdfdcbe-014b-4b68-9ac5-976d384106c3
< 1.9.3
MEDIUM 6.4 The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TypeOut T… wordfence
4fdefb32-8fab-4f22-bc61-a53f92a06a12
< 11.12.6
MEDIUM 6.4 The PowerPress Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
4fd76fbc-22df-4071-a2ae-9c9ac9cdbc57
< 10.11.0
MEDIUM 6.4 The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is… wordfence
← Prev 667 668 669 670 671 672 673 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top