πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 695 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
39695b53-9af7-42f0-8bde-3969398a7186
< 3.3.27
MEDIUM 6.4 The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
3949a3a9-b02b-415a-a418-73756f6355a5
< 10.9
MEDIUM 6.4 The Greenshift plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 10.8 … wordfence
394732cc-94b5-4fbf-bd78-da18791724be
< 1.3.12
MEDIUM 6.4 The Evenium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'evenium_single_event' sh… wordfence
393d6e4a-af05-48ac-8921-f298932245a4 MEDIUM 6.4 The STM Gallery 1.9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'composicion' parameter in… wordfence
393d1b30-19f8-454d-84c0-0b539953e1fe
< 1.1.11
MEDIUM 6.4 The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' a… wordfence
393193b2-25b4-485c-a9c6-fbe075ebd6f9
< 2.5.1
MEDIUM 6.4 The WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.0 … wordfence
39286096-2efa-450b-b491-b3d40de5a4ae MEDIUM 6.4 The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_noti… wordfence
3921f323-a525-46db-9cb7-989fa1375984 MEDIUM 6.4 The codeSnips plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2 du… wordfence
3906c668-6a0a-4beb-8ed9-08f661ce82cf
< 3.11.0
MEDIUM 6.4 The Easy Appointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in ve… wordfence
38fbdd82-73ed-4be0-874e-1dfced29dc7d
< 3.9.1
MEDIUM 6.4 The Livemesh Addons for WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
38ec1a6b-f5ee-446a-9e6c-3485dafb85ac
< 4.15.3
MEDIUM 6.4 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
38ebe1d4-4ac0-4d03-8945-451902263442
< 3.2.9
MEDIUM 6.4 The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes … wordfence
38eaf4be-5083-46fe-b586-e4be190dc9cc
< 1.0.342
MEDIUM 6.4 The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_loo… wordfence
38e5dd9e-c017-4b4c-9064-76a07e30fab5 MEDIUM 6.4 The Wueen plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wueen-blocket` shortcode i… wordfence
38dd95b2-d747-44f3-a3f5-d32221381554
< 45.0.1
MEDIUM 6.4 The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Bloc… wordfence
38cb5e43-56d0-40b6-936a-f10f15d2e72f
< 2.0.4
MEDIUM 6.4 The Simple Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all … wordfence
38af4b11-c36a-441e-b49c-c3ad9ddfd210
< 3.2.6
MEDIUM 6.4 The Gallery Blocks with Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
38a87046-9a46-40c2-b10d-d1a7d5ef8742
< 2.3.4
MEDIUM 6.4 The Favorites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'user_favorites' shortc… wordfence
38a3b3bf-9538-4ae8-9da4-d4b48805763b MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion… wordfence
389d96e9-1fad-49a6-89b6-8f7f108d8117
< 4.4
MEDIUM 6.4 The WP SVG Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜type’ parameter in all … wordfence
3895df7a-9f24-45a5-b447-16f214cfbfcc
< 1.2.20
MEDIUM 6.4 The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmeventlist' short… wordfence
38702239-604a-415c-a8f5-2444d937727e
< 2.1.16
MEDIUM 6.4 The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
38537a5e-7e36-4c94-9d27-59a53dada47b MEDIUM 6.4 The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl… wordfence
38483c50-52cf-44c5-9bc4-c5dc0baee162 MEDIUM 6.4 The Elegant Themes Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
3830ae19-cafc-40db-afde-2424cae23031
< 3.14.9
MEDIUM 6.4 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is… wordfence
← Prev 692 693 694 695 696 697 698 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top