🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 694 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3a46cebe-8009-4902-a751-8a4267915380
< 4.1
MEDIUM 6.4 The Zoho Billing – Embed Payment Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
3a3aeefb-7d9c-4d2a-bc32-8fa2030151fa
< 1.10.0
MEDIUM 6.4 The WebHotelier plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.… wordfence
3a3147b5-0362-4299-8339-655eaade948e
< 2.0.0
MEDIUM 6.4 The WPFAQBlock– FAQ & Accordion Plugin For Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
3a2460ab-2f45-4ee2-a3ef-77e769a678d0
< 1.5.2
MEDIUM 6.4 The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Phone', 'Dial Code… wordfence
3a1d8adf-c49c-4d88-83c7-4515b0ab1f35 MEDIUM 6.4 The PDF Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.0 … wordfence
3a196eaa-64c7-447b-9384-b58fcba57ec0 MEDIUM 6.4 The LeadBI Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_id' para… wordfence
3a152cbd-1452-483c-8780-afa8054c3686
< 1.9.3
MEDIUM 6.4 The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.2… wordfence
39f6fb61-25a9-4386-9b61-7343760fd28c
< 3.6.0
MEDIUM 6.4 The Sina Extension for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sina… wordfence
39f26d35-a702-49fc-aed1-0a329ac32553
< 2.9.2
MEDIUM 6.4 The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu … wordfence
39ea4627-66b2-42a6-913e-04c708491b8d MEDIUM 6.4 The DesignThemes Core Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versi… wordfence
39e58875-2f6e-453e-b33f-3d7a2a62b7b6
< 1.3.0
MEDIUM 6.4 The WP Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprtabs' shor… wordfence
39e1a681-f1ab-4da4-9328-822e1cc92551 MEDIUM 6.4 The Display Terms Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
39e104fa-591a-41e8-af7e-f8b32a199170
< 2.5.3
MEDIUM 6.4 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
39d189ca-d9f9-4ed9-bfc0-6c1402a9fd18
< 3.2.22
MEDIUM 6.4 The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
39c8e951-8e8c-4a72-9ecf-1dd96392105d
< 5.5.5
MEDIUM 6.4 The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
39c651c3-a478-4f58-af51-fd73d2934bdf
< 3.6.4
MEDIUM 6.4 The Contempo Real Estate Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versio… wordfence
39c4a5ec-ade7-4bfc-9cde-93621e3f255b
< 1.0.9
MEDIUM 6.4 The HT Mega – Absolute Addons for WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
39b9e8a0-96bb-4b36-b4e8-ec9e3f137835
< 5.3.15
MEDIUM 6.4 The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_name’ parameter… wordfence
39b2435f-32a3-4158-a734-c21a0cab15be
< 7.3.0
MEDIUM 6.4 The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG … wordfence
39b0af74-f773-4a56-b169-2ee11e923813
< 5.10.15
MEDIUM 6.4 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for… wordfence
39acd470-d65b-415d-9f57-2227d19821df MEDIUM 6.4 The WP-Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.1 … wordfence
39a3450e-f3c2-4c89-985d-28e23eb433dd MEDIUM 6.4 The External Media plugin for WordPress is vulnerable to File Upload due to insufficient file type validation in the isU… wordfence
399b0bb0-37e1-4207-b3f5-2ded33c3d967
< 1.8.7
MEDIUM 6.4 The BRW plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.6 due to… wordfence
3999c48f-bae6-48ea-b35f-d8307d9c3898
< 3.0.14
MEDIUM 6.4 The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized malicious SVG file uploads in versions … wordfence
3991d8d0-57a8-42e7-a53c-97508f7e137f MEDIUM 6.4 The Instagram for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions… wordfence
← Prev 691 692 693 694 695 696 697 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top