🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 685 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
43039c47-a34f-4020-9009-473e93468e21
< 3.0.2
MEDIUM 6.4 Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/… wordfence
43014ecd-72d9-44cc-be24-c0c9790ddc20
< 5.9.9
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
42f68a01-ef94-4e7e-abdd-46571973b911
< 11.9.18
MEDIUM 6.4 The PowerPress Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast URLs in versions… wordfence
42e54e09-242f-49ab-9fff-a9ffc62dd4bd
< 3.9.3
MEDIUM 6.4 The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in v… wordfence
42de41f1-cfb2-4413-8841-c63d0e764be3
< 2.0.8.3
MEDIUM 6.4 The The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) plugin for WordPress is vulnerabl… wordfence
42dd1eeb-10b4-48f1-b392-dfa3a9d4b9c4
< 3.7.30
MEDIUM 6.4 WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can … wordfence
42db52ae-f881-4082-b475-8577a28641c6
< 2.9.8
MEDIUM 6.4 The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in… wordfence
42dacf78-1feb-4cbc-9ec3-805e668be931 MEDIUM 6.4 The Easy Chart Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
42d862ef-523f-43ca-a3fb-ac3fbb537c46
< 1.4.7
MEDIUM 6.4 The Statify Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
42d56d6a-365a-4fa2-977f-a1328e0ec1b3
< 1.6
MEDIUM 6.4 The Clicky by Yoast plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user settings in versions up t… wordfence
42cf84d1-37f5-41c1-838d-67244f17c55d MEDIUM 6.4 The Particle Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'particlegrou… wordfence
42c1d2ea-dea6-4cde-8db3-37709da9eb71
< 1.9.0
MEDIUM 6.4 The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multi… wordfence
42bbe73f-3465-4e84-8de9-43a85500f316
< 5.8010
MEDIUM 6.4 The Ebook Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.80… wordfence
42b682be-1a60-449d-8c92-72bd1c3abfd6
< 0.0.11
MEDIUM 6.4 The Caching Compatible Cookie Opt-In and JavaScript plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
42b49a88-c6b7-47ac-89ab-c2e0d7f1c7cc MEDIUM 6.4 The wp_amaps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7 due… wordfence
42ad6fef-4280-45db-a3e2-6d7522751fa7
< 3.6.8
MEDIUM 6.4 The FareHarbor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and i… wordfence
42a0345a-4ad9-4cad-a7ef-2f5661fa855f
< 5.10.5.2
MEDIUM 6.4 The TheGem Theme Elements (for WPBakery) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
429f697c-e101-4fc3-ab9f-557c932bded5
< 1.1.11
MEDIUM 6.4 The Web Bricks Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
428d44c2-ef30-4d34-8f62-030af9931441
< 3.4.0
MEDIUM 6.4 The Gutenberg Blocks – PublishPress Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '… wordfence
428b4d6b-a4db-4e60-8c15-24efdfe6aea1
< 3.2.0
MEDIUM 6.4 The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
4281ad41-d9a4-4503-9238-24990641a9bf MEDIUM 6.4 The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-events' shortcode in v… wordfence
42816fa2-98a7-41c6-95d9-d0bac259d741
< 2.0.5
MEDIUM 6.4 The Uix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
42743c2f-053b-4f14-bf11-865f978ec017
< 2.8.00
MEDIUM 6.4 The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parame… wordfence
42629244-dd2f-4ae1-9b35-e59a71b8005b MEDIUM 6.4 The PF Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.0 d… wordfence
426280c1-0ecb-4973-915e-bb63ac240bca
< 3.1.36
MEDIUM 6.4 The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
← Prev 682 683 684 685 686 687 688 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top