πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 691 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3dee74dc-32ae-47cd-8797-dbba60387702 MEDIUM 6.4 The IMGspider – ε›Ύη‰‡ι‡‡ι›†ζŠ“ε–ζ’δ»Ά plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers… wordfence
3de98970-06a3-4bde-a7cb-42b6456fea6c MEDIUM 6.4 The Responsive flipbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
3ddc7519-3ef0-449c-8190-fe0972c62703
< 3.34
MEDIUM 6.4 The Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
3ddb9c46-683d-4eb4-a30f-f492d4f3ae2d
< 6.6.10
MEDIUM 6.4 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Store… wordfence
3dd6c562-3c1e-46a3-bd02-bb587d8e6c76
< 9.0.5
MEDIUM 6.4 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
3dd66c4f-46f8-46d2-b424-beb6ecc69675
< 1.7.6
MEDIUM 6.4 The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
3dd3dc4b-e936-46a4-8d65-5f4bf05b2374
< 1.5.1
MEDIUM 6.4 The Basticom Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver… wordfence
3dcf401a-3b91-4b55-b6b1-a132ec195607 MEDIUM 6.4 The A/B Testing for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ab-tes… wordfence
3dc0349b-a802-46a0-9d2b-f52b34c93a7f
< 3.12.9
MEDIUM 6.4 The YMC Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.12.… wordfence
3daa3a7d-bb92-41c7-92ad-71f6ff0bb50a MEDIUM 6.4 The ClickFunnels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in vers… wordfence
3da0a44f-d4b4-4330-a2e3-d25a2a7df926
< 2.2.0
MEDIUM 6.4 The WP Meta and Date Remover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versi… wordfence
3d99bc37-4697-400a-bbd4-858543f17d1f
< 1.10.4
MEDIUM 6.4 The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
3d91158c-0b34-460e-9fdb-b99165ebca78 MEDIUM 6.4 The Coachific Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userhash' shortcode a… wordfence
3d81e41d-e62c-49d7-bba5-6a2a0a586c84
< 2.4.14
MEDIUM 6.4 The Kali Forms β€” Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
3d768e52-0fd3-4404-8936-6b6069f7e98f MEDIUM 6.4 The ACF Recent Posts Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
3d61758e-39a5-4f6a-8d88-7c44210eb69a
< 5.5.0
MEDIUM 6.4 The K Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.5.0 due to insuffic… wordfence
3d3fcadf-60bd-4a2e-a30c-e276dd04368c
< 1.3.9.3
MEDIUM 6.4 The WOOCS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and includi… wordfence
3d2b4c27-e446-43bf-9d6b-6856222fa3a4
< 1.3.7
MEDIUM 6.4 The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
3d24f5d8-a1dc-4dc6-86ac-296f7df71560 MEDIUM 6.4 The ListingPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.9… wordfence
3d0bf4d1-ba07-4204-bb2b-cdee10e6a275
< 3.5.4
MEDIUM 6.4 The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) … wordfence
3d066dea-5a7a-4944-9c6b-a30affd324fa MEDIUM 6.4 The WPBakery Visual Composer WHMCS Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
3d03cecc-8788-4e81-9b01-42539eba88f7
< 2.2.3
MEDIUM 6.4 The Change Add to Cart Button Text for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
3cf570e4-7cae-4adc-ac3e-84225d74da39
< 2.2.3
MEDIUM 6.4 The Email Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '$log_item' variable in versions… wordfence
3cd8bed0-fcfe-4927-b393-ddabbe8c3e6b
< 2.9.5
MEDIUM 6.4 The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cro… wordfence
3cad7928-dbbd-4c64-a409-2f1f5302ff1a MEDIUM 6.4 The Adventure Bucket List plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
← Prev 688 689 690 691 692 693 694 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top