πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 679 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
486f43cc-cc3f-4a63-b00f-86f29a391269 MEDIUM 6.4 The king_IE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to… wordfence
485ec722-b6d2-44f9-924e-dcea17dca03e MEDIUM 6.4 The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.7 … wordfence
485c9ee6-9cb5-45ca-86af-ee5d10ee6734
< 2.0.6.8
MEDIUM 6.4 The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin fo… wordfence
485b0f47-fb3c-49f5-8e27-c250879cb75f MEDIUM 6.4 The Lordicon Animated Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
48514fdb-20c6-4a7f-8f60-e532ddd8853e MEDIUM 6.4 The Curved Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'radius' parameter of the arct… wordfence
48511d1a-2fd5-4be4-8409-e99d4aadcdfe
< 3.9.11
MEDIUM 6.4 The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gu… wordfence
483564f8-6308-4913-82e2-78d69aebb6dd
< 5.2.2
MEDIUM 6.4 The YouTube Embed WordPress plugin before 5.2.2 does not validate, escape or sanitise some of its shortcode attributes, … wordfence
482bf861-e556-40af-b522-c22ef6c9938b
< 4.0.2
MEDIUM 6.4 The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
480ba214-2669-478a-a5fc-2bf563d99f7c MEDIUM 6.4 The Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.… wordfence
48086577-09fc-4406-b13f-2091b50d1719 MEDIUM 6.4 The Lenxel Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.… wordfence
4806b44b-b3f5-4bc2-897f-786df8459bd3
< 5.2.2
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
47f0795c-5a79-47e8-b118-f4f0e95ac53b
< 3.0.16
MEDIUM 6.4 Stored XSS in Salutation Responsive WordPress + BuddyPress Theme version 3.0.15 could allow logged-in users to do almost… wordfence
47f05812-b873-4092-9014-20ca1d0e484a
< 2.16.2.1
MEDIUM 6.4 The Knowledge Base documentation & wiki plugin – BasePress Docs plugin for WordPress is vulnerable to Server-Side Requ… wordfence
47f051dd-138c-4c71-8a92-150c9ffd3601
< 3.0.3
MEDIUM 6.4 The Currency Converter Widget – Exchange Rates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
47ee441a-4285-4bed-ac9d-b146fd502e46 MEDIUM 6.4 The Sailthru Triggermail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in a… wordfence
47e25cfa-fedf-413a-bfe7-18a1de429bc3
< 8.1.12
MEDIUM 6.4 The ActiveCampaign – Forms, Site Tracking, Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
47db93d6-3181-4b83-afa3-1d3a45df24c7 MEDIUM 6.4 The Kodex Posts likes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
47d4cf6a-400f-4001-95de-f93e574bb2ef
< 5.3.3
MEDIUM 6.4 Cross-site scripting vulnerability in WordPress Popular Posts 5.3.2 and earlier allows a remote authenticated attacker t… wordfence
47cd99ef-d9b0-4be3-8dc4-d7dd56f37c1c
< 2.1.8
MEDIUM 6.4 The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
47baeaee-de6b-4459-a211-177859427e70 MEDIUM 6.4 The Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several shortcode attributes in version… wordfence
47ab93d2-0e1d-42b0-a6ea-05300eae8da7
< 2.1.4
MEDIUM 6.4 The WP Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.1.… wordfence
47a04186-8eec-4ef6-9fce-9b891a04ed9f MEDIUM 6.4 The Responsive iframe GoogleMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'responsive_ma… wordfence
47853750-0bf1-4df3-9c56-c6852543cfad
< 1.5.97
MEDIUM 6.4 The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link fiel… wordfence
477b41a5-b2ff-4b94-9622-824146a0e2ed
< 5.1.4
MEDIUM 6.4 wordfence
477281fb-00ba-4ba0-a2fa-9f0e9379db26
< 3.4.4
MEDIUM 6.4 The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
← Prev 676 677 678 679 680 681 682 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top