ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 687 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
413e3430-2d9b-4b14-90da-99de44b393e3
< 1.2
MEDIUM 6.4 The WPB Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
413a6508-b94a-4131-bc1a-af278bd9b6f0 MEDIUM 6.4 The Sermon Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
4135e93e-596d-4ada-86ad-4f161e7ed38e
< 2.2.17
MEDIUM 6.4 The Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
41315d40-0e93-480a-b85f-f3e4c8fa299a
< 2.0.3
MEDIUM 6.4 The Bulk Auto Image Title Attribute plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
411d6ca0-933a-4c68-9681-7fce9eb34c9d
< 1.2.7
MEDIUM 6.4 The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point… wordfence
4117683b-5827-406c-aaaf-b01e9fdb1ba7
< 2.5.0
MEDIUM 6.4 The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to Sto… wordfence
4113a88f-5203-4fe6-9fb4-c59a63174418
< 8.2.6
MEDIUM 6.4 The Soledad theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4 due t… wordfence
4111ba11-ad79-466a-9669-3c35730a331a
< 4.10.29
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the subcontainer … wordfence
41116b52-8f94-4d29-8845-a27bdf817b43 MEDIUM 6.4 The Sermon Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sermon-views` shortcode in… wordfence
40f0510a-06e3-40a9-9b93-0296f524f94a
< 1.5.149
MEDIUM 6.4 The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widge… wordfence
40e8dc83-6417-4881-a9a3-15525c5cc6ba MEDIUM 6.4 The ESV Bible Shortcode for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
40e1215c-ac00-4fd6-b428-a57cef95aed1
< 1.18.3
MEDIUM 6.4 The Popup Maker – Popup for opt-ins, lead gen, & more plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
40ca3778-95ff-4b2c-ac47-4ae8c86e245a
< 1.3.972
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image… wordfence
40c5dd26-6063-4ab2-a370-464e84d806b7
< 9.88.2.0
MEDIUM 6.4 The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile setti… wordfence
40bd7bf4-1132-4c13-a422-0741b106b1ea MEDIUM 6.4 The Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.1 du… wordfence
40aeb258-0c00-4cd3-944c-51c33a7e92c9
< 5.4.0
MEDIUM 6.4 The Custom Query Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
40acd95e-9afd-4c84-b19a-a45117c0fcde
< 3.3.4
MEDIUM 6.4 The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-… wordfence
40a94a1e-da9e-4173-a21d-106d859c7f8c
< 1.43
MEDIUM 6.4 The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in vers… wordfence
40a883e8-7ce0-4fca-a585-428b67144694
< 1.6.8
MEDIUM 6.4 The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets i… wordfence
40a272dc-cb2a-472f-be42-733efcb2fa61
< 1.2.3
MEDIUM 6.4 The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button… wordfence
40873fcd-4161-4862-ac73-8046159f4739
< 3.0.8
MEDIUM 6.4 The Menu Image, Icons made easy WordPress plugin before 3.0.8 does not have authorisation and CSRF checks when saving me… wordfence
40733449-7953-452e-aa11-60306be9bc5d
< 1.1.4
MEDIUM 6.4 The WP Show Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ‘order’, 'orderby', and othe… wordfence
406ec4be-12de-45fa-861a-83d26d2ac401 MEDIUM 6.4 The Slides & Presentations plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
406951d8-4c61-45b3-a8a2-788921662b6c
< 1.0.0
MEDIUM 6.4 The ActivityPub plugin for WordPress is vulnerable to Stored Cross-Site Scripting via certain post content in versions u… wordfence
40560df9-2e54-4613-94c5-c03da0e78409
< 7.1.4
MEDIUM 6.4 The Enfold theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.1.3 due … wordfence
← Prev 684 685 686 687 688 689 690 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top