🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 699 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
35f9614c-032f-499e-a777-05725be3bd7a MEDIUM 6.4 The Penci Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5… wordfence
35ee465c-3958-4fcb-b1a8-e01ebc4a045a MEDIUM 6.4 The WordPress HTML plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0… wordfence
35ead2b5-8b50-40e1-9b4a-547d97f34c4e
< 3.10.0
MEDIUM 6.4 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
35def866-7460-4cad-8d86-7b9e4905cbe4
< 0.5.3
MEDIUM 6.4 The CallRail Phone Call Tracking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'callrail_for… wordfence
35cb9b4e-223a-48ba-af6f-a9d6d2f3db03 MEDIUM 6.4 The RSV 360 View plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0… wordfence
35c5c75c-a595-48cd-acec-a83f5c422f18 MEDIUM 6.4 The amazing neo icon font for elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
35c40c81-c7b4-4453-bd2f-7910fcb7f13e
< 2.1.8
MEDIUM 6.4 The My Agile Privacy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in … wordfence
35bd7462-8dab-43b2-9941-fef6f826cfdc
< 5.30.4
MEDIUM 6.4 The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to,… wordfence
35b9f37c-69e1-437a-97dd-3d3e7a8cd86e
< 4.8
MEDIUM 6.4 The Ivory Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in version… wordfence
35b3a8cd-1fc7-4176-ace6-580dd92c6154
< 6.0.7
MEDIUM 6.4 The Premium Packages plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
35b0d959-2adb-4de4-b51b-1bfead49bc7d
< 3.6.2
MEDIUM 6.4 The Pet-Manager – Petfinder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the kwm-petfinder sh… wordfence
35a5114e-5c5f-4003-8bb3-77243ffbac1a
< 7.7
MEDIUM 6.4 The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link attribute wi… wordfence
35969379-e668-4045-8de7-696f196ba5b0
< 3.4.8
MEDIUM 6.4 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Tim… wordfence
35958bea-29f2-4364-b476-fefba51689c6
< 1.7.0
MEDIUM 6.4 The Back Button Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
358be91d-cb00-429b-a4ed-69bf81e4d19e
< 1.2.2
MEDIUM 6.4 The Fonto – Custom Web Fonts Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File up… wordfence
358b595b-9e4b-4bf9-ac4f-03683c284078
< 2.2.7
MEDIUM 6.4 The WP Social Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
358a1a87-a87c-41b9-addc-d4945cd8fb40
< 1.1.25
MEDIUM 6.4 The Productive Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_producti… wordfence
357b848c-65e9-4267-af53-55d133ca47d4 MEDIUM 6.4 The Emoji Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
356549d0-8b74-4dd5-bef0-bf8c22d1f040 MEDIUM 6.4 The Easy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
3557cd1e-cfb4-4f08-af3c-be5211a325c1 MEDIUM 6.4 The Sparkle Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
3548241e-551e-427a-907c-50b4712b5e5b
< 1.6.135
MEDIUM 6.4 The Mesmerize Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up t… wordfence
354631ff-ed01-45d0-b275-cbd96fffff5a MEDIUM 6.4 The Mapme plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2 due … wordfence
353d22c5-dee1-485f-ae66-e9c7afe3ad8e
< 4.5
MEDIUM 6.4 The Team Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘new_style_name’ parameter… wordfence
3539fe09-c158-4146-9850-446bc32e7bec
< 2.7.2
MEDIUM 6.4 The Exclusive Addons Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
3533909d-9c81-4687-9426-187ceae2656e
< 2.2.93
MEDIUM 6.4 The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
← Prev 696 697 698 699 700 701 702 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top