🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 684 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
43bb402e-4c61-4d1c-9992-528642372629
< 4.1.0
MEDIUM 6.4 The WP jQuery DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
43aa28ec-6553-4527-a1d1-eb4a58533c5d
< 1.3.0
MEDIUM 6.4 The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'no_… wordfence
439ef0bb-cfac-4d81-b858-46a9837ad58f MEDIUM 6.4 The Testimonials Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
4397c99c-c37d-43da-9285-003ba91d4003
< 8.3.1
MEDIUM 6.4 The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘animated_… wordfence
438fbd3f-052b-4a6d-acd2-233a93d56cbb
< 3.7.40
MEDIUM 6.4 WordPress Core in versions up to 6.0.3 and the Gutenberg plugin for WordPress in versions up to 14.3.1 are vulnerable to… wordfence
438e2911-7663-44fe-883f-19ad29972aac
< 1.2.2
MEDIUM 6.4 The Icon List Block – Add Icon-Based Lists with Custom Styles plugin for WordPress is vulnerable to Server-Side Reques… wordfence
438b9c13-4059-4671-ab4a-07a8cf6f6122 MEDIUM 6.4 The Shortcode Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shortmenu' shortcode in versio… wordfence
438a94c4-a7f2-4c08-960b-e18c19196169
< 1.6.0
MEDIUM 6.4 The BZScore – Live Score plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(… wordfence
43854ca5-02ba-4926-9a5e-d9fd5b1af448
< 1.13.42
MEDIUM 6.4 The PickPlugins Product Slider for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
43841cbd-e78a-4b67-a495-208146cfe108
< 1.5
MEDIUM 6.4 The Simple Spoiler plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
43825586-1a0b-4297-b278-77c1846be9aa
< 11.13.12
MEDIUM 6.4 The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Server-Side Request Forgery in all ver… wordfence
437e4f77-6426-411f-985e-35e1a1f30bfb MEDIUM 6.4 The WordPress Widgets Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
4379f2c5-3533-45f7-a4ef-0b3320eb5d04
< 1.1
MEDIUM 6.4 The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic… wordfence
4377ee4a-7016-42a2-94a2-60338cbe4b12 MEDIUM 6.4 The Image Editor by Pixo plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
4377b12c-b118-4284-8532-474473658ea5
< 3.1.6
MEDIUM 6.4 The Quick Interest Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i… wordfence
435e8ca8-cf00-4de9-a454-8cb09b7661ef
< 3.0.1
MEDIUM 6.4 The Ed's Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `eds_font_aweso… wordfence
435e1af0-c4f4-42ae-b2b3-2d9ffc41c4b5 MEDIUM 6.4 The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) v… wordfence
433c8908-587e-4086-9d0c-c9b1819b26e8
< 2.2.1
MEDIUM 6.4 The WP Tabs – Responsive Tabs Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
433b5d92-5eca-4b60-94b1-e6288470955b
< 1.9.7
MEDIUM 6.4 The Easy Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
4339400c-1f6f-4a3f-85f2-28bd7246b949
< 3.0.0
MEDIUM 6.4 The Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
4335e598-d48b-4dbe-b6a4-69790acecfdd MEDIUM 6.4 The Stripe Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stripe_donation'… wordfence
4333ba20-e201-4424-b483-4751e86384e2 MEDIUM 6.4 The Gutenberg Blocks – ACF Blocks Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
4322d9d6-13b6-4476-9eb5-fea4aff2e5ce
< 2.0.33
MEDIUM 6.4 The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's EE Event… wordfence
43192613-ce5b-4acc-b284-f40cad7cb8df
< 1.4.6.8
MEDIUM 6.4 The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
4308528d-6a7e-462b-a6a3-b8f59c0c16bc MEDIUM 6.4 The OS Our Team plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7 … wordfence
← Prev 681 682 683 684 685 686 687 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top