🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 681 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
46693edf-bcc6-4af8-9f26-5ede865f4694
< 4.2.6.6
MEDIUM 6.4 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘lay… wordfence
465af9c6-9687-4417-96fb-b7df3d221a1a
< 2.3.10
MEDIUM 6.4 A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Conse… wordfence
463fea25-c793-42fc-a8a8-28d001978133
< 4.16.3
MEDIUM 6.4 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
4633c5b1-a6e3-4ee8-94ca-8afa8ff16a35 MEDIUM 6.4 The Minimum Purchase for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
462060ec-1661-4807-8e64-fa624ba2cc98 MEDIUM 6.4 The EMC2 Alert Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
46202ea3-9825-4492-b188-0ddc934e81e8
< 7.0
MEDIUM 6.4 The Shopkeeper Extender plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 7.0 due to i… wordfence
461fedd6-8138-46ee-9c76-dc71061242bf
< 1.2.0
MEDIUM 6.4 The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… wordfence
461ab75a-3ced-4296-9dc1-b8eee17a8299
< 1.3
MEDIUM 6.4 The Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
45f98a96-8f32-49f9-bfc8-9beb316ce0bc
< 1.1.4
MEDIUM 6.4 The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-c… wordfence
45f81b33-ced8-4ada-978f-f15c68ef4eef
< 4.0.3
MEDIUM 6.4 The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
45ef20aa-18e3-4ad8-a94e-76e29de5b562
< 6.0.8
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for … wordfence
45e96aa3-97bb-4774-a1b5-5f0a7b18293e MEDIUM 6.4 The League of Legends Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in ver… wordfence
45d7fe64-c51b-4801-a190-92396e5db27d
< 5.1.3
MEDIUM 6.4 The Employee Spotlight – Team Member Showcase & Meet the Team Plugin plugin for WordPress is vulnerable to Stored Cros… wordfence
45cd04bb-d3a0-48af-97ac-c5d668d665df
< 1.0.3
MEDIUM 6.4 The Archive Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0… wordfence
45c7f8fb-3fd0-425f-89a1-8971f67d5755
< 1.4.0
MEDIUM 6.4 The Medialist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all ver… wordfence
45c6c041-91b0-4abe-ba72-ec1251651fdb
< 2.2.5
MEDIUM 6.4 The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slide… wordfence
45c1888e-ea46-43b9-bfab-069a972fa9a2 MEDIUM 6.4 The Annie plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 due … wordfence
45b3ae9c-20a8-4b04-a49f-b02865dfd79c
< 3.7.28
MEDIUM 6.4 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Stored C… wordfence
459f6d68-ce52-4e63-8fd9-071ef517a3ce MEDIUM 6.4 The Tabs Shortcode and Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortco… wordfence
458f6544-88f2-41e9-b6f8-9af9b03d991f MEDIUM 6.4 The Pay With Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
45850fe1-017b-4bfa-aeb0-73e495e74c0e MEDIUM 6.4 The Minical Hotel Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
457b5066-da37-4877-9abe-c912bc201f29
< 6.7.11
MEDIUM 6.4 The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu… wordfence
45792c95-8abf-4d0c-85a1-cda6f505949d
< 2.7.4
MEDIUM 6.4 The Video Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in … wordfence
45785032-2bbf-4398-94a1-f819f8e8a9ca MEDIUM 6.4 The ULeak Security & Monitoring WordPress plugin through 1.2.3 does not have authorisation and CSRF checks when updating… wordfence
45754b5b-8f94-4806-a931-bb423450682c
< 2.3.7
MEDIUM 6.4 The Stagtools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in version… wordfence
← Prev 678 679 680 681 682 683 684 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top