🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 700 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
35151561-6a80-4c2c-b87a-2dfe02aa6158
< 2.9.13
MEDIUM 6.4 The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Global Badge module in … wordfence
350719b1-0e88-4f6f-979e-0ac3d17b852b
< 2.1.5
MEDIUM 6.4 The Shortcode for Current Date WordPress plugin is vulnerable to Stored Cross-Site Scripting via Shortcodes due to missi… wordfence
34d8c67a-548f-4498-8b57-33c0e7e5c004 MEDIUM 6.4 The Fyrebox Quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
34d21418-4faf-40bf-a960-79482a592722
< 7.6
MEDIUM 6.4 The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title tag attribute in all v… wordfence
34ce7fa9-5f38-49f0-b402-34fdf8ee80dc MEDIUM 6.4 The Nirvana theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.3 due… wordfence
34c64a8b-32ad-4349-b593-933fc057d1a6
< 5.9.9.3
MEDIUM 6.4 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
34c13495-23c3-4b07-9bfb-678723daa43f MEDIUM 6.4 The Tips Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tip' shortcode in all vers… wordfence
34b11b26-7e8a-48b4-98e9-9a2a3778cbd1 MEDIUM 6.4 The ProfilePro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1… wordfence
34a94f59-3ff4-473d-9f95-f1f8abfb3985
< 1.0.7
MEDIUM 6.4 The Mega Menu Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
34a5649c-8fb0-43ed-9b63-16c798280b75
< 1.0.8
MEDIUM 6.4 The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
34a42180-9d08-4049-8da8-27ee1f64600a
< 2.6.4
MEDIUM 6.4 The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image box widge… wordfence
349ba9de-69b3-42fb-aeba-c3a24280547f
< 51.1.63
MEDIUM 6.4 The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' p… wordfence
347feeaa-2d5c-4818-ab9e-2125a00b8ae8
< 6.4.12
MEDIUM 6.4 The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for W… wordfence
347ba90e-b65f-46ea-bc82-8b5eb5dd5bdd
< 2.3.1
MEDIUM 6.4 The Visual Link Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inc… wordfence
347b2fac-34ec-455a-97ff-c64781a6ec1a
< 8.7.23
MEDIUM 6.4 The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.7.23 du… wordfence
34706986-0181-4e9e-a826-7fe3a9171f98 MEDIUM 6.4 The SKT Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5 d… wordfence
346c9785-0069-40ec-a255-fe2dae30f7a0
< 3.13.9
MEDIUM 6.4 The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and com… wordfence
34578df8-661c-4c54-b06c-e1d787ca3c55 MEDIUM 6.4 The The Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘clientId’ parameter in … wordfence
3456e10c-39fc-46a4-8f82-49fbc5a34860 MEDIUM 6.4 The WP DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.2… wordfence
343ed594-482a-4a27-9682-92bb643ee82a
< 4.1.16
MEDIUM 6.4 The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to… wordfence
343a6dbd-baf5-4de8-ae3e-6954fd3f1556 MEDIUM 6.4 The Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WP… wordfence
342d6941-6987-4756-b554-1699128b9108
< 3.8.4
MEDIUM 6.4 The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu… wordfence
342ccae4-2e77-4a4f-963f-689b882eb7f0 MEDIUM 6.4 The Responsive Food and Drink Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's di… wordfence
340c14ea-70b9-4f60-84b3-97328432f110
< 27.6.2
MEDIUM 6.4 The Betheme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom JS functionality i… wordfence
34097a1d-a7cb-4c72-80dd-c84796b6632d
< 1.4.3
MEDIUM 6.4 The WP Travel Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
← Prev 697 698 699 700 701 702 703 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top