🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 689 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3f83a514-2b42-4348-9525-438205daeeab MEDIUM 6.4 The OneElements – Best Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File… wordfence
3f7616d0-7b42-4b2e-8378-18c24c7bf22b
< 1.2.05
MEDIUM 6.4 The Namasha By Mdesign plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘playicon_title’ pa… wordfence
3f749054-7aeb-4d37-ba2a-5f15028b2571
< 2.1.0
MEDIUM 6.4 The Blog, Posts and Category Filter for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in v… wordfence
3f6c7142-22e6-4221-bbcf-eaa2795d361e
< 1.0.14
MEDIUM 6.4 The Custom iFrame for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
3f507853-8c9f-4308-ad6e-5fbb610158f5
< 1.0.3
MEDIUM 6.4 The Event Tickets, RSVPs, Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 't… wordfence
3f417afd-2822-412f-b68a-f09c013d6049
< 3.12.10
MEDIUM 6.4 The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
3f3d6028-37ea-495d-aeb0-8f7cc940d2fd MEDIUM 6.4 The Page Builder: Live Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
3f378797-a7a7-4691-8d37-1caef454bb4f
< 7.0.0
MEDIUM 6.4 The Quiz and Survery Master plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the text editor and co… wordfence
3f2e54e1-bec5-478b-9bb6-09cee967470b
< 2.0.15
MEDIUM 6.4 The Futurio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
3f2c8c5f-2017-4b22-a864-dc142b3b1afb
< 1.2.9
MEDIUM 6.4 The Precious Metals Charts and Widgets for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
3f28b1b2-e751-423e-b4c5-893778eebf3f
< 1.0.6
MEDIUM 6.4 The IFrame Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in ver… wordfence
3f1c13f6-150c-4634-a4d8-176a4d7a2296
< 1.7.0
MEDIUM 6.4 The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup class parameter in a… wordfence
3f1a34cc-a961-4bcd-a95c-ae6009f1f274
< 1.6.3
MEDIUM 6.4 The Product Time Countdown for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… wordfence
3f04b52f-8100-4823-b925-ed562f08a91d MEDIUM 6.4 The Incredible Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
3f0082c6-c040-4244-be7b-b133fd24d093
< 3.111.1
MEDIUM 6.4 The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Sto… wordfence
3efb5f5c-64d2-4819-82bf-45574df94209
< 3.8.8.1
MEDIUM 6.4 The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attri… wordfence
3ef94c4b-fba3-4595-b073-7300d1972d6c
< 8.3
MEDIUM 6.4 The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
3ef87ab8-d56b-4d3a-b4fc-6c17c24143ec
< 5.0.1
MEDIUM 6.4 The Software Issue Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg par… wordfence
3eddc03d-ecff-4b50-a574-7b6b62e53af0
< 7.6.16
MEDIUM 6.4 The wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of an up… wordfence
3edafcfc-3343-452d-b389-733b21c4a3aa
< 2.3.5
MEDIUM 6.4 The Click to Chat – WP Support All-in-One Floating Widget plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
3ed59d5b-0922-44e9-98e8-07b91d1f4840 MEDIUM 6.4 The Glofox Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glofox' and 'g… wordfence
3ec7f51d-5d65-40ff-9fe5-0fa6d5225fba
< 1.0.3
MEDIUM 6.4 The Plotly plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.2 due… wordfence
3ec77f96-c73a-44f7-afa2-673f68ee3582 MEDIUM 6.4 The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,… wordfence
3ec14212-2112-41b5-9361-596df5ad9bb4 MEDIUM 6.4 The Vehica Core plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.0.… wordfence
3ebd05d5-a65d-49df-a865-882e9d17fc0f
< 1.1.51
MEDIUM 6.4 The WooCommerce Box Office plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
← Prev 686 687 688 689 690 691 692 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top