πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 682 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
45726bd2-5b32-4b7b-b990-8ede3aae107e MEDIUM 6.4 The Carousel-of-post-images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
456377ec-1a73-4f9b-9fdf-0b5597e78aa5
< 1.45.2.1
MEDIUM 6.4 The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
455fb4af-47cf-42d5-8232-f00442bca761 MEDIUM 6.4 The Shine PDF Embeder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shinepdf' shor… wordfence
4542b0f8-c9ee-4992-b737-e5f727c7b5b0
< 10.2.0
MEDIUM 6.4 The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'show_l… wordfence
454091ac-8765-4bda-ac6e-69537b43f9a7
< 3.0.3
MEDIUM 6.4 The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in… wordfence
453dc1f9-0b79-467c-9344-21d3ed06a9d0 MEDIUM 6.4 The Minamaze theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.10.1 d… wordfence
4529464e-6830-4c2a-8146-79cf5fc1bc7c
< 1.3.985
MEDIUM 6.4 The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
4514bd5d-05bd-4e9d-bd44-9a594d8c4145
< 1.0.0.37
MEDIUM 6.4 The Gallery for Social Photo plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an… wordfence
44e68e0c-1b21-411b-9ff7-6b6affc5988e
< 1.0.2
MEDIUM 6.4 The Smart Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜id’ parameter in … wordfence
44e53c69-e301-4007-b090-c277e9f07905 MEDIUM 6.4 The Capitalize My Title plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
44e4fb1b-eed4-4ef9-9856-7c5095117aa7
< 2.0.9.1
MEDIUM 6.4 The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin fo… wordfence
44d1c85a-9a19-4962-9db3-539fa5702d2f
< 1.6
MEDIUM 6.4 The WP FullCalendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
44d041ca-caa6-410d-b2d1-7a63208cc512
< 4.3.7
MEDIUM 6.4 The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysb… wordfence
44bae6d6-e6ee-441b-b517-4636a8ec99b9 MEDIUM 6.4 The WP Githuber MD plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
44b8659a-c88d-44d3-8eab-71b0a49d97b4 MEDIUM 6.4 The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the… wordfence
44b2d11d-e876-433e-9e0d-5e9f2b3c0c80
< 2.0.5
MEDIUM 6.4 The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
44b173da-a6b9-424c-95a1-a87a9b8ee4af
< 2.4.8
MEDIUM 6.4 Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Featherlight.js Ja… wordfence
44acba71-c1f1-4f10-a817-ca9b7e878bd3
< 3.3.0
MEDIUM 6.4 The Verowa Connect plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3… wordfence
44a62dd2-539a-4d9a-a32e-f935aa1d0d58 MEDIUM 6.4 The WP Mermaid plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.2… wordfence
4493aba1-d18d-4511-86ec-b10b36d0c0df
< 1.0.10
MEDIUM 6.4 The Donation Forms WP by Givecloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
4492aede-b68d-46b8-955f-81ebdc875921
< 1.7.2
MEDIUM 6.4 The Borderless – Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
4486b797-352d-4cab-9495-9e476bd41526
< 2.0.5
MEDIUM 6.4 The Themify Audio Dock plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
447d3aa6-2ed3-4da3-b9e8-fc7792c8c29a
< 1.0.4.2
MEDIUM 6.4 The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
4475cbd4-07cf-499a-a11a-b63eb9184568
< 2.3.5
MEDIUM 6.4 The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
4474c79b-f93a-4725-8345-ad5c5260913c
< 3.1.37
MEDIUM 6.4 The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lw_content… wordfence
← Prev 679 680 681 682 683 684 685 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top