πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 690 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3eb84fa6-1e06-4368-9d9e-4b601b9a1b93
< 3.7.3
MEDIUM 6.4 The Porto Theme - Functionality plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
3eb74ac2-ac5d-477b-8142-3e42953f859b
< 1.6.10
MEDIUM 6.4 The Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site plugin for WordPress is vulnerable t… wordfence
3ead3aee-3d72-4fc0-a613-700ec75fb0bb
< 2.1.4
MEDIUM 6.4 The Simple Tooltips plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in ver… wordfence
3ea00ce9-e48f-4641-844c-ced7db60d62d
< 1.0
MEDIUM 6.4 The Layers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'webcam' shortcode in all … wordfence
3e9bcc72-e434-4f6f-9e90-eec8cad31035 MEDIUM 6.4 The Islamic Phrases plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phrases' shortcode attrib… wordfence
3e8ff1f4-1217-4bb5-ba2d-6d2ff847072a
< 1.7.4
MEDIUM 6.4 The Easy PayPal Buy Now Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortc… wordfence
3e85543e-bad3-4415-8b10-cecaac7742ce
< 1.2.6
MEDIUM 6.4 The Generic Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
3e7eed9d-2d44-4951-b66b-7d8995ca617d
< 6.1.0
MEDIUM 6.4 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Store… wordfence
3e7d7245-59aa-4dfa-88b8-b8e054fba7bf MEDIUM 6.4 The DELUCKS SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.… wordfence
3e7d10ab-2525-407b-b814-ef7d884d5287 MEDIUM 6.4 The Content Cards plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all… wordfence
3e7bd708-2e82-4fef-85f2-bf4f56f66bc4
< 3.2.2
MEDIUM 6.4 The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native ga… wordfence
3e60a315-7f74-4d81-b6d2-ad3d40d489ef MEDIUM 6.4 The SearchWiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in search results in all… wordfence
3e5cf0f0-f933-4782-82b9-099b65371c89 MEDIUM 6.4 The Advanced Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
3e4aaf2e-a0c6-47d2-9eb8-d65952a74424
< 1.0.6
MEDIUM 6.4 The OneClick Chat to Order plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(… wordfence
3e3b5433-e17b-4ece-9e5c-ef4d818068dc MEDIUM 6.4 The BrightTALK WordPress Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'format' sh… wordfence
3e348b24-4c49-43ed-b4f3-b31f0f709830
< 2.0.1
MEDIUM 6.4 The Bukza plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bukza' shortcode in all ve… wordfence
3e343ea3-996c-47c7-9480-e6264cbded98
< 5.10.6
MEDIUM 6.4 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… wordfence
3e2e8dfb-df74-41b7-9b3b-0f5d7b1c545b
< 6.1.5
MEDIUM 6.4 The YOP Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.1.4 d… wordfence
3e10e25e-7d92-4374-8c8e-479cc0dabb1c
< 4.5.25
MEDIUM 6.4 The Media Cloud for Bunny CDN, Amazon S3, Cloudflare R2, Google Cloud Storage, DigitalOcean and more plugin for WordPres… wordfence
3e1008ad-daa9-4785-9dd5-4cdeb10d7e59
< 2.4.41
MEDIUM 6.4 The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block uplo… wordfence
3e0da463-2ba0-43ca-927c-55c12643ef32
< 2.0.8
MEDIUM 6.4 The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Backgrou… wordfence
3e0be093-d61a-4634-ba9b-91dd7328e8cd
< 16.26.12
MEDIUM 6.4 The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
3e067b10-aa78-4cef-b3fd-b91595c54a37
< 21.9.0
MEDIUM 6.4 The Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 21.8.2… wordfence
3e047822-5766-4e7f-be89-f4a15f0e6d51
< 4.3.0
MEDIUM 6.4 The Forms Bridge – Infinite integrations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id… wordfence
3df02341-e5f6-46d7-a511-1e6d0772167a MEDIUM 6.4 The Image Carousel Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
← Prev 687 688 689 690 691 692 693 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top