πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 692 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3c9cc5d4-7ddc-4af7-b433-7d75db739970
< 1.4.6
MEDIUM 6.4 The DSGVO Youtube plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… wordfence
3c8571b2-9260-4970-89f6-f711574e0f7c
< 4.1.0
MEDIUM 6.4 The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versi… wordfence
3c6eec02-d67c-417d-a6d6-cbf240de0eee
< 1.1.3
MEDIUM 6.4 The Counters Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
3c6949f9-316c-4e48-a77a-ace793d329ac MEDIUM 6.4 The Pixobe Cartography plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
3c5640b6-f59d-407e-a553-c3834390104f MEDIUM 6.4 The Map Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
3c55e673-93af-403e-a690-2ae02c63541f
< 1.1.4
MEDIUM 6.4 The SuevaFree Essential Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'counter'… wordfence
3c51dcd7-0ca4-449b-819c-91de1dacad03 MEDIUM 6.4 The Crazy Call To Action Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
3c32eb5b-dc4b-42f6-8454-d2ad57d7051d
< 2.7.3
MEDIUM 6.4 The BuddyForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.… wordfence
3c3217f9-67e5-488d-b80a-49a61678fb98
< 6.4.12
MEDIUM 6.4 The Plus Addons for Elementor plugin for WordPress was vulnerable to Authenticated (Contributor+) Stored Cross-Site Scri… wordfence
3c2ecb9d-2496-4bbc-b55e-28fb5df1b397
< 2.0.2
MEDIUM 6.4 The WP To Do plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.0 d… wordfence
3c298653-7f79-4ee2-89c8-8a6d0e1446b8
< 3.9.2
MEDIUM 6.4 The Smartsupp – live chat, AI shopping assistant and chatbots plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
3c22d064-348d-4335-beaf-22dcdcf88518
< 4.2.5
MEDIUM 6.4 The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Si… wordfence
3c1250cb-7678-4cbc-97ff-3983e076f516 MEDIUM 6.4 The Header Footer Composer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
3c10df7c-4bca-4ed7-b2ba-1a7f046d814e MEDIUM 6.4 The Leartes TRY Exchange Rates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
3bfe1d81-9b0a-4998-8702-173795b8f493
< 2.0.30
MEDIUM 6.4 The Beds24 Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bookwidget… wordfence
3bfde56f-298a-4718-aa48-25ff11f538a3
< 2.10.8
MEDIUM 6.4 The Doneren met Mollie plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
3bf77988-370b-437f-83a0-18a147e3e087 MEDIUM 6.4 The Awesome Weather Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'awesome-weather' short… wordfence
3be5e544-1ea5-46f6-a15b-99b0e3718c91
< 4.0.5
MEDIUM 6.4 The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
3bd09891-8117-43b1-8744-8f3773971540
< 6.4.7
MEDIUM 6.4 The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
3bcd4da7-db9d-41ee-88d7-1b55e6166ea0 MEDIUM 6.4 The External Video For Everybody plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
3bcb87df-5cd3-4234-ad17-c40eacabd305
< 2.0.1
MEDIUM 6.4 The Extend Link plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … wordfence
3bbe6b57-9c50-4515-aa62-a9d9a41bf4ce
< 2.7.8
MEDIUM 6.4 The Jobs for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… wordfence
3bba8002-8106-493c-aeb2-b7189190fb3d MEDIUM 6.4 The EventON Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.9.… wordfence
3bba2901-55a7-4ef1-ab3c-1415aa99c729
< 3.6.3
MEDIUM 6.4 The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageAlt' block attribute in … wordfence
3bb9520d-e679-4e8a-ae3c-8207f17d45a2
< 2.12.0
MEDIUM 6.4 The Simple Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `pro_version_activation_code… wordfence
← Prev 689 690 691 692 693 694 695 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top