🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 683 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4473d3f6-e324-40f5-b92b-167f76b17332
< 3.19.0
MEDIUM 6.4 The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Si… wordfence
446fadbc-b927-4245-9095-fd545a906b9a MEDIUM 6.4 The History Timeline plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
446c7cb2-4050-4414-ba3c-f832ea7d6c5c MEDIUM 6.4 The Posts Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2… wordfence
446aa338-b020-431d-a68b-b8239de3150c MEDIUM 6.4 The Email Inquiry & Cart Options for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… wordfence
4457d15e-2c01-498d-b94a-a6e93adcf70c
< 1.0.18
MEDIUM 6.4 The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_type’… wordfence
444f6a49-9d7a-4661-bab7-06d16f5f0317 MEDIUM 6.4 The The Great Firewords of China plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to… wordfence
44445c44-5ae0-4f2b-8096-aa94ae5ff0b6
< 2.9.2
MEDIUM 6.4 The Create theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.1 due … wordfence
443f0664-cc9c-4e82-bde3-72cbab285cc7 MEDIUM 6.4 The Elegant Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
443d2e80-31db-40ac-9c35-88eec841ebba
< 2.4.0
MEDIUM 6.4 The Tracking Code Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tracking code field … wordfence
443cfb7b-4566-4a71-ac31-5a5361c58aa2
< 1.3.3
MEDIUM 6.4 The Discover the Best Woocommerce Product Brands Plugin for WordPress – Woocommerce Brands Plugin plugin for WordPress… wordfence
443ceb13-bc6e-4d8d-a415-1a0d4fecf38e
< 2.0.5
MEDIUM 6.4 The ConvertKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions… wordfence
443c314f-c767-4169-bfdd-5d6c2d61dd39 MEDIUM 6.4 The (dp) AddThis plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0… wordfence
44370988-3c55-490e-b428-da9cb6df1a4b
< 1.13
MEDIUM 6.4 The CPT Bootstrap Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode … wordfence
44362245-a3af-46a5-b35b-eabd5f537fca MEDIUM 6.4 The Ird Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irdslider' shortcode … wordfence
442995ed-bf92-4fa7-a0a2-341cb87d8fbb
< 4.5
MEDIUM 6.4 The Embed Calendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4… wordfence
441bc9fe-3dd6-40a6-b7f3-36511115c083
< 7.7.10
MEDIUM 6.4 The LayerSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.7.… wordfence
44132f7b-31d4-46e9-8441-e27f0f4c5789
< 1.0.8
MEDIUM 6.4 The Active Products Tables for WooCommerce. Use constructor to create tables  plugin for WordPress is vulnerable to Sto… wordfence
440242e5-832f-4796-9317-b377e1c2fa2a
< 3.6.2
MEDIUM 6.4 An issue was discovered in the All in One SEO Pack plugin before 3.6.2 for WordPress. The SEO Description and Title fiel… wordfence
43fc4752-7a47-480c-82e2-54821e754f7f MEDIUM 6.4 The Advanced Most Recent Posts Mod plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
43f976ee-cba7-4f5d-b9c6-a6f66c0011d2
< 1.8.6
MEDIUM 6.4 The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Remote Code Execution in versions up to 1… wordfence
43f1a954-df53-46c6-9ecf-5fd50f490cfb
< 1.6.2
MEDIUM 6.4 The Better Post & Filter Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers… wordfence
43e52adf-387c-452d-96b4-aad459fa75b3 MEDIUM 6.4 The BuddyHolis ListSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listsearch… wordfence
43d141e3-1e62-4126-b914-bdc98577de3f MEDIUM 6.4 The Easy Org Chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3… wordfence
43ca15b7-8cb4-427f-892d-15022da17b2e MEDIUM 6.4 The TCBD Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbdtooltip_text' s… wordfence
43bc48a5-d97c-48ad-a80d-07f327ee859b MEDIUM 6.4 The Simple Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
← Prev 680 681 682 683 684 685 686 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top