πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 693 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3bb30dac-e0f3-43dd-a20d-9af6c7af3cb4
< 1.0.72
MEDIUM 6.4 The NewsMash theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versio… wordfence
3bb0d712-5a0f-4526-bb24-2ce96bdd039b MEDIUM 6.4 The Boxed Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
3ba9f117-c314-47ad-8af1-5294b529d95c MEDIUM 6.4 The OpenMenu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5 due… wordfence
3ba995c6-e577-4e26-af6e-d236449a993d MEDIUM 6.4 The Clyp plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3 due to … wordfence
3b7ab552-1ec5-4479-84b9-3e44f6c0354d MEDIUM 6.4 The Power Ups for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'magic-bu… wordfence
3b70f48f-76a6-459c-8108-3ca008471534 MEDIUM 6.4 The Recent Posts Widget Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rpw… wordfence
3b6916d3-3944-43a2-8d5e-424f86c753ad
< 8.5
MEDIUM 6.4 The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
3b5decc1-cc81-4a5e-b6d8-5120cb37c93b
< 3.3.3
MEDIUM 6.4 The Posts List Designer by Category – List Category Posts Or Recent Posts plugin for WordPress is vulnerable to Stored… wordfence
3b5253ad-19c1-4f79-9b12-c41ec60fee69
< 1.5.5
MEDIUM 6.4 The Salient Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
3b497a36-4929-413f-abfc-1d81bfaa7889 MEDIUM 6.4 The Advanced Page Visit Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
3b3f0f80-0004-4373-b0a7-92f2d047415d MEDIUM 6.4 The Print Button Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'print-button' shor… wordfence
3b3e793a-4290-4e0e-b5d4-d6acd83e5c3b
< 3.9.1
MEDIUM 6.4 The Editorial Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
3b3bb703-fdff-4525-9272-7a3db58b81a0
< 1.2.9
MEDIUM 6.4 The Simple SEO Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in a… wordfence
3b39e58c-3fb6-40ce-af25-9b1a9c59e97a MEDIUM 6.4 The BWL Knowledge Base Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
3b3170d0-3b9c-41dc-a08e-4d5bbaa7e89f MEDIUM 6.4 The DImage 360 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0 d… wordfence
3b2ef7c3-4610-4e8b-ab27-2d6cbdbed097
< 2.6.9
MEDIUM 6.4 The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploa… wordfence
3b1e84a0-10c3-42a9-ab9f-89b5b0a84526
< 4.0.16
MEDIUM 6.4 The Praison SEO WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
3b08f533-9c74-4be3-99ff-70a3d9b90358 MEDIUM 6.4 The TCBD Popover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd-popover-image … wordfence
3afdffa7-23ec-41ea-b05a-152a69b7ce50 MEDIUM 6.4 The WDES Responsive Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wdes-popup… wordfence
3ad9fcd1-b3a3-4711-ad23-d27c3e2091f4
< 23.3
MEDIUM 6.4 The WordPress Online Booking and Scheduling Plugin – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
3ac8a509-e54b-40e7-9fd8-4aef03168827
< 260805
MEDIUM 6.4 The s2Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 260804 … wordfence
3a9715c3-6ce0-46f8-820d-194bd0e8e6fd MEDIUM 6.4 The Lazy load videos and sticky control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… wordfence
3a9427b6-d5b0-4727-962e-cab829aff230 MEDIUM 6.4 The Luzuk Team plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.1.0… wordfence
3a7b15ce-ff0e-4693-8ceb-afa341306dc3
< 1.1.15
MEDIUM 6.4 The Findus - Directory Listing WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the severa… wordfence
3a59b749-1134-42bf-83bd-62202e1e151f MEDIUM 6.4 The Sliding Door theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6 … wordfence
← Prev 690 691 692 693 694 695 696 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top