πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 680 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
47716128-949c-4215-9fd7-bccb51c532c8 MEDIUM 6.4 The TheFox theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.9.70 due… wordfence
476c4eb3-db28-4f6a-9502-969e7f1c5ec1
< 2.0.2
MEDIUM 6.4 The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver… wordfence
475f2758-27a5-4a36-8085-576ee341938b
< 0.1.12
MEDIUM 6.4 The Spotlightr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotlightr-v' shortco… wordfence
4759a9a9-0e1d-41e2-b04d-a0578e925208 MEDIUM 6.4 The PressForward plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,… wordfence
474fdbcb-fe3c-4a79-a847-363f81b300c2
< 1.0.219-beta
MEDIUM 6.4 The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜id… wordfence
473bef81-b2c9-429c-aa23-c2dba0908cc3
< 3.29.1
MEDIUM 6.4 The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
472dc1aa-d6b6-4f9d-99c2-ac5b1b417a3e
< 8.7.13
MEDIUM 6.4 The Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons plugin for WordPress … wordfence
4711e3d5-b70c-413e-97e7-6d2e93e8217e
< 2.6.2
MEDIUM 6.4 The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in … wordfence
4701efb1-4208-4178-90c0-bfc006d1a72a
< 6.3.0
MEDIUM 6.4 The Modern Events Calendar Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown paramet… wordfence
46f144c9-2cd3-4320-b987-119b672e7e30
< 1.2.4
MEDIUM 6.4 In the Schiocco "Support Board - Chat And Help Desk" plugin 1.2.3 for WordPress, a Stored XSS vulnerability has been dis… wordfence
46e66230-06d6-452e-a7aa-862b2bb8c27d
< 7.6
MEDIUM 6.4 The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt paramet… wordfence
46e53bf4-49af-45d8-b672-1f9b2f2dd91f
< 4.7.7
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the css class in versions up… wordfence
46e47284-2757-40d0-ac76-292a690cfcbb
< 1.4.9
MEDIUM 6.4 The ConeBlog – WordPress Blog Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
46e15cc0-0a1c-4268-a431-e943526b12f7 MEDIUM 6.4 The Ebook Downloader plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
46d4d573-3845-4d20-8a48-a2f28850383c
< 4.15.0
MEDIUM 6.4 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
46d3693b-61b5-4d93-a584-76b207c76806 MEDIUM 6.4 The Horizontal Line Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
46abb44e-bfa8-4b36-bd5d-b27e18fbb0f3
< 4.9.0
MEDIUM 6.4 The Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin plugin for WordPress is vulnerable to Store… wordfence
46978e1d-7adb-49f6-8e41-093f177c9a4d
< 4.4.8
MEDIUM 6.4 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress … wordfence
46868a11-0c82-4bd3-82b5-9a19a5a0cef1
< 2.6.5
MEDIUM 6.4 The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit - Banner w… wordfence
46825646-f611-4e9d-bee8-36656a1d54ff
< 0.2.2
MEDIUM 6.4 The WP Front End Profile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜save-fields.php’… wordfence
467d5c09-2425-4050-98ca-a7c5d533af77
< 2024.04.30
MEDIUM 6.4 The Swift Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Caption Title in all versions … wordfence
46731877-03e1-4552-8993-3b121b457b1b
< 6.7.6
MEDIUM 6.4 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cro… wordfence
467261ba-f41f-4e94-8941-e5b3d8392fdb MEDIUM 6.4 The Nonaki – Drag and Drop Email Template builder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
4671b103-1240-4508-81ce-6b8573658021 MEDIUM 6.4 The PilotPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.3… wordfence
466fc6f3-7b2d-4975-a838-16e27bc9f9b5
< 4.9
MEDIUM 6.4 The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button shortcode … wordfence
← Prev 677 678 679 680 681 682 683 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top