πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 678 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
49589caf-232b-4067-a607-2902e932553e MEDIUM 6.4 The Clients plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.4 du… wordfence
49581614-14a8-4450-8f83-d8d22a3feee9
< 2.0.79
MEDIUM 6.4 The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerabl… wordfence
4956eb18-92b8-4ba3-89a8-71edf08dc502
< 4.1.1
MEDIUM 6.4 The Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… wordfence
49460db5-a0cd-4b29-85f2-8ededabf5599 MEDIUM 6.4 The Social Proof (Testimonial) Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
491c7680-d270-41ed-a756-9397a0bd86bc MEDIUM 6.4 The Charts Ninja: Create Beautiful Graphs & Charts and Easily Add Them to Your Website plugin for WordPress is vulnerabl… wordfence
4917652a-1c83-4570-98c5-1a34e637814e
< 6.2.3
MEDIUM 6.4 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to DOM-B… wordfence
490944a6-96e8-4416-a63b-c7a7ba9172ae
< 1.13.7
MEDIUM 6.4 The Clean Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in version… wordfence
49005688-fa40-458d-9c96-5ec2ca7adcd3 MEDIUM 6.4 The Visualmodo Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads … wordfence
48fdece5-2996-426f-b77c-ae0b35bcd0ce
< 4.10.29
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's post… wordfence
48fa5f3b-000b-406e-b7ee-51af5720cf72
< 2.9.13
MEDIUM 6.4 The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's IHover widget … wordfence
48f42d27-18eb-4606-beb5-c3bfe9f72647 MEDIUM 6.4 The News, Magazine and Blog Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
48ee5ef5-0fac-496d-b770-91aa846ed5a9
< 7.9
MEDIUM 6.4 The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all v… wordfence
48e62d66-d058-419c-93cf-0cb890177751 MEDIUM 6.4 The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skipto' shortcode in al… wordfence
48e2129f-6a2c-45e4-a0cf-7d8d5f563a7f
< 5.3.6
MEDIUM 6.4 The Modal Window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and… wordfence
48c114d7-3d53-4157-a335-19cf4b47eed5 MEDIUM 6.4 The Simple Football Scoreboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ytmr_fb_scoreb… wordfence
48bf9bf4-1b8a-41cc-adc9-a618d075c7f2
< 6.4.0
MEDIUM 6.4 The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule p… wordfence
48b9f3e3-b7fd-4d7c-8f8b-b11ed977aa92
< 17.6.0
MEDIUM 6.4 The Surbma | GDPR Proof Cookie Consent & Notice Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
48b66fb1-2b3e-499d-bf1f-3c445f4b5e3a MEDIUM 6.4 The AchillesTheme-shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
48b47968-e853-4f32-b66e-8a25e1d7009d
< 2.7.7
MEDIUM 6.4 The FluentCommunity – Ultra-Fast High-Performance Social Network, Community, LMS & Online Courses plugin for WordPress… wordfence
48a13fb7-bf1a-4bf2-ac3b-3b5a75fec616
< 2.6.5
MEDIUM 6.4 The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget's attri… wordfence
4890cd48-a448-4af1-ae1e-6456300434e5
< 5.5.3
MEDIUM 6.4 The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordP… wordfence
488ac848-786e-4100-a387-5a40e8fc4175
< 3.6.2
MEDIUM 6.4 The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜url’ parameter in ver… wordfence
487731cd-da5a-45b6-8f39-4ae6420dd252
< 4.15.9
MEDIUM 6.4 The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ProfilePress User Panel widge… wordfence
4876e05e-efa6-46c6-832b-9ecc42934998
< 8.3.5
MEDIUM 6.4 The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions… wordfence
486ffdc9-a3e7-4f4c-89b1-b668a5d41aa5 MEDIUM 6.4 The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to Stored Cr… wordfence
← Prev 675 676 677 678 679 680 681 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top