🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 697 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
37db075a-c335-4532-86cb-8cfa2897e02e
< 2.5.9
MEDIUM 6.4 The WP AdCenter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.… wordfence
37d48295-357b-47c3-9adf-ce49dc73f337
< 4.2.9
MEDIUM 6.4 The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
37c18340-d7aa-4410-be17-c61c286838ce
< 2.7.4
MEDIUM 6.4 The Jobs for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via "Working Hours" in all vers… wordfence
37afe2eb-0671-4dba-babc-f0b286dcb84f
< 1.1.12
MEDIUM 6.4 The HelloAsso plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.11… wordfence
37ab838d-7247-40db-8d78-e3f84116b415
< 0.1.37
MEDIUM 6.4 The BlockStrap Page Builder - Bootstrap Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers… wordfence
37a4a181-82ba-43bd-9caf-3a56cacb86a9
< 2.3.28
MEDIUM 6.4 The GigPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up… wordfence
379b8a8a-bb6f-435f-a2bd-e3569e7b142e
< 1.4.0
MEDIUM 6.4 The WPCasa plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2 due… wordfence
379825e2-61bf-4d11-8eea-05ad08200e9e
< 4.1.18
MEDIUM 6.4 The Church Admin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘meta-text’ parameter in … wordfence
3785938d-d55a-487d-8709-2d3bdd4b8c0f
< 1.3.4
MEDIUM 6.4 The Workscout Core WordPress plugin before 1.3.4, used by the WorkScout Theme did not sanitise the chat messages sent vi… wordfence
377e232b-1245-48ff-9f79-26a049e20063 MEDIUM 6.4 The Course Migration for LearnDash plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up … wordfence
37731e51-33ce-4ef3-8a13-976c005dc983
< 10.9.3
MEDIUM 6.4 The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' sho… wordfence
376e2638-a873-4142-ad7d-067ae3333709
< 2.1.2
MEDIUM 6.4 The Feeds for YouTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube-feed' shortcode in … wordfence
376404a5-176e-4c73-8281-27b138218879
< 1.8
MEDIUM 6.4 The WP Flipclock plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the flipclock display settings in… wordfence
3763d893-83a0-4b6a-9c21-34a69313d555
< 4.2.2
MEDIUM 6.4 The Save as PDF Plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's… wordfence
375ed04b-a3cb-4e60-83c8-18bff583aaf4
< 2.5.2
MEDIUM 6.4 The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field meta values in all ver… wordfence
37506a9e-a225-4519-a24e-8678c31cc106
< 3.6.1
MEDIUM 6.4 The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
374c0b68-4f06-4b81-9bf9-a43a868e1e7b MEDIUM 6.4 The WPSHARE247 Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
374a26dd-dd62-4583-8aff-90e5ae6b7468 MEDIUM 6.4 The My Geo Posts Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mygeo_city' shortcode i… wordfence
37326225-60b8-4d80-8db5-22421f0dc427 MEDIUM 6.4 The Tooltipy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.9 d… wordfence
372f1cf3-df33-444c-b31e-8f71d128e30b
< 3.2.2
MEDIUM 6.4 The Map Block Leaflet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in a… wordfence
372632cb-8dfd-4d74-a765-c8fb9d0f1b78
< 2.3.3
MEDIUM 6.4 Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web sc… wordfence
37236f49-c853-4594-bb33-6dba55ed0a07 MEDIUM 6.4 The Directory Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
37223d1f-82c8-414f-bf39-63e728541aa3
< 1.7.1002
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Googl… wordfence
371e0f8b-4e2c-4425-a77d-7cbe1adba8e2
< 1.2.2
MEDIUM 6.4 The RPS Include Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
3710f219-545f-421d-a654-f49169ff7808
< 1.3.2
MEDIUM 6.4 The Time Clock – A WordPress Employee & Volunteer Time Clock Plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
← Prev 694 695 696 697 698 699 700 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top