πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 688 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
405590c7-2ad2-4a04-b1e2-bb1ad6da8dde
< 1.3.4
MEDIUM 6.4 The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
405378f8-7a93-4672-a2d4-d250ec8adcf3 MEDIUM 6.4 The Master Slider Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
40502842-8505-41fb-9d3a-a5d567040921
< 3.7.19
MEDIUM 6.4 In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrat… wordfence
404fc2d1-0c5d-4734-980e-ae3ac293d1f3
< 5.9.5.3
MEDIUM 6.4 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Server-Side Request Forg… wordfence
40488ed8-ab4c-4ba6-821e-ed6d7a63e260
< 1.3.3
MEDIUM 6.4 The Hotel Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions … wordfence
402e10b4-84f0-4f93-a85c-037876d26e58
< 2.4.0
MEDIUM 6.4 The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Dynamic Tag Injection in HTML A… wordfence
402d0399-bc48-4740-86a4-8bf3424fb035
< 1.3.0
MEDIUM 6.4 The OSM Map Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜id’ p… wordfence
4028fe14-eca4-4bc5-9374-084377a97461 MEDIUM 6.4 The Bamboo Enquiries plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
40153d8a-b661-40bf-aaf5-90527def9fd7
< 6.4.1
MEDIUM 6.4 The Nasa Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 6.4.1 due to insuffici… wordfence
400564ba-70f8-4566-b2e7-cfa6450b609e
< 2.3.1
MEDIUM 6.4 The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kbalert' shortcod… wordfence
3ff96d74-8f20-49a6-bd02-0bfe3498b599
< 3.5.3
MEDIUM 6.4 The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpme… wordfence
3ff54694-64c4-4112-b126-aabd3e09144b
< 2.0.8
MEDIUM 6.4 The Qyrr – simply and modern QR-Code creation plugin for WordPress is vulnerable to arbitrary file uploads due to miss… wordfence
3fef9990-023a-4d4b-8c52-3b71aac97e7b
< 1.5.3
MEDIUM 6.4 The Loan Comparison plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes like 'amo… wordfence
3feb5f46-e861-40ec-84e8-aade0667eec6 MEDIUM 6.4 The Open Hours – Easy Opening Hours plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'… wordfence
3fe2f85d-0d68-49f0-8e0b-8d09c463be79 MEDIUM 6.4 The Category Featured Images Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
3fe1f3c3-4a81-4aae-9a5e-e5889f4c69ba
< 1.6.0
MEDIUM 6.4 The Table Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wptableeditor_vtabs… wordfence
3fe03c7b-9a98-4479-ba91-ab662dcddf6a
< 2.3.81
MEDIUM 6.4 The GeoDirectory plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3… wordfence
3fd6469c-bf36-4a46-a899-8d5163df8935
< 10.0.10
MEDIUM 6.4 The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
3fd620a3-5d9e-4bc3-b026-871610df7c2d
< 1.2.2
MEDIUM 6.4 The Linker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versio… wordfence
3fc2c2df-b590-413f-ba07-5aa645d069b8
< 2.9.1
MEDIUM 6.4 The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor… wordfence
3fb6123c-2891-4cfd-8d68-a922c30d7600
< 1.1.5
MEDIUM 6.4 The Spectra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block ids in all versions up to, a… wordfence
3fa41a0a-ee17-4b6a-b973-ab70bcd7622e
< 1.0.2
MEDIUM 6.4 The Post in page for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
3f9d57ae-b238-43db-8eee-ccab499b1cbc MEDIUM 6.4 The fyyd podcast shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fyyd-podcast', 'f… wordfence
3f8e363d-60ec-4e86-856c-c4ffc11fe690 MEDIUM 6.4 The jQuery googleslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'googleslides' shortco… wordfence
3f8dced7-cbe1-4d50-9fa0-1cf441dddefa MEDIUM 6.4 The WP Js List Pages Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortc… wordfence
← Prev 685 686 687 688 689 690 691 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top