🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 698 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3706deed-55f2-4dfb-bfed-7a14872cd15a
< 4.7
MEDIUM 6.4 The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `iframe` shortcode in versions up t… wordfence
3705f028-9c8d-48b1-8950-160e10038294
< 2.15.8
MEDIUM 6.4 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
36f7eb57-76ac-4130-abb3-6521f9d042ce MEDIUM 6.4 The WHA Puzzle plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.9… wordfence
36e9e069-b649-4824-9388-36d8cb9cae49 MEDIUM 6.4 The Mindmeister Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
36e070de-bd77-48a4-a9c2-3938b144398a
< 3.0.0
MEDIUM 6.4 The Counter Up – Animated Number Counter & Milestone Showcase plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
36dcf1c4-1e0a-4ab6-a1b3-a9fe3aaddd0b MEDIUM 6.4 The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
36d57b8d-7e62-413b-8ea9-87963b8cd469
< 1.4.0
MEDIUM 6.4 The AffiliateX – Amazon Affiliate Plugin plugin for WordPress is vulnerable to unauthorized modification of data due t… wordfence
36ca4534-1abe-4f28-8672-f183c7578ab2
< 4.0.3
MEDIUM 6.4 The MainWP Code Snippets Extension for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
36c3107d-f125-4715-999e-8862e4103313 MEDIUM 6.4 The Post Views Count plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in … wordfence
36b5eb39-4edc-4f17-a764-d07f39114ef0 MEDIUM 6.4 The Easy Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
36806418-ae4e-4981-b9c5-dadb5e92e69a
< 1.2.0
MEDIUM 6.4 The Lana Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, … wordfence
367bb24c-ba88-4809-a620-759d3c8dcd38
< 1.2.7
MEDIUM 6.4 The Responsive Google Maps | by imbaa plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
367a7796-b94b-4239-894f-01bf71cdeed9
< 1.3.7
MEDIUM 6.4 The Gum Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
36759c8a-351b-448c-a79e-05465e99b4c2
< 4.3.2
MEDIUM 6.4 The Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and … wordfence
36724ac4-330d-4614-b30c-b1e2e6d6b8a9 MEDIUM 6.4 The Genesis Club Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
365d4470-1fad-455f-827b-59c5cab2852a
< 2.7.12.3
MEDIUM 6.4 The JetElements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
3657384e-025a-44ad-8b7e-1a2fea17dcc3
< 12.4.1
MEDIUM 6.4 The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_name’ parameter in ve… wordfence
3643c741-559b-438b-9a39-518b9a6dfbf4
< 2.8.0
MEDIUM 6.4 wordfence
36409b31-be48-455e-b591-cda8bd84214e
< 2.2.2
MEDIUM 6.4 The WPAdverts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.1 … wordfence
3639d0a6-6d9f-4f3e-bb25-85d4eb40b547
< 1.2.0
MEDIUM 6.4 The Ultra Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
36310ab1-f84e-4154-b782-51254c476d79
< 1.32.18
MEDIUM 6.4 The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'i… wordfence
362a01c0-8b97-40dc-8af5-0d904da96576
< 2.4.7
MEDIUM 6.4 The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'oceanwp_icon' shortc… wordfence
3623e004-b33f-4e28-b190-429eb3c2498d
< 2.1.9
MEDIUM 6.4 The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
3621801a-231b-4678-bfb5-fbf18e58a658
< 1.81
MEDIUM 6.4 The WP External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versio… wordfence
3602bc88-b966-4eac-98fa-2ab49bb971c0
< 4.8
MEDIUM 6.4 The SearchIQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7 due… wordfence
← Prev 695 696 697 698 699 700 701 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top