πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 701 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
33f673b5-2bcb-4591-b589-4d7230b5c2e7 MEDIUM 6.4 The FL3R Accessibility Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fl3racce… wordfence
33f63bd9-3031-40e8-b72e-1cbbcce5b782
< 0.4.9
MEDIUM 6.4 The Squelch Tabs and Accordions Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜… wordfence
33e7006f-3fb9-4493-9ce5-67698c877159
< 3.1.1
MEDIUM 6.4 The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
33d7dc4d-bb41-456a-bd1a-37d8f2aada30
< 1.13
MEDIUM 6.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button1_icon' at… wordfence
33cfdad9-d335-4721-990d-54109d7673a0
< 15.8
MEDIUM 6.4 The WP GoToWebinar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
33cba63c-4629-48fd-850f-f68dad626a67
< 5.1.4
MEDIUM 6.4 The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filter_array' paramete… wordfence
33c2756d-c300-479f-b3aa-8f22c3a70278
< 1.8
MEDIUM 6.4 The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in… wordfence
33b5e231-1b53-4646-ae9c-48babf1ebbd7
< 2.5.0
MEDIUM 6.4 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
33a91dd0-2589-4bb4-886b-1832a216205b
< 1.5.6
MEDIUM 6.4 The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
33a1230f-c1d6-4bc1-b3f4-9c45f47332a4
< 1.0.7
MEDIUM 6.4 The Dynamic Post Grid Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
338d9348-da24-44b9-ac97-a7a8a7376815
< 1.1
MEDIUM 6.4 The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'njte… wordfence
338003bb-0569-4b9b-aa98-37153fb7e9c3 MEDIUM 6.4 The Gutenium Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
337d052c-6ee2-4cd0-8a69-a4b66b25517a
< 3.5.3
MEDIUM 6.4 The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… wordfence
337cbec1-c8a8-41b5-8c32-779be671120f
< 1.3.972
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
3379dde1-d1fb-4ec8-b834-de00fb6a38f2
< 3.7.33
MEDIUM 6.4 In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to sc… wordfence
336e2429-97ab-4948-9d21-f0121216d2d1
< 2.2.26
MEDIUM 6.4 The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is… wordfence
33581898-067b-445c-8ad0-12ff4778a13c
< 1.6.0
MEDIUM 6.4 The Creative Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wid… wordfence
334ecb1e-027c-4a0f-88cb-34b02482f097 MEDIUM 6.4 The Simple Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the text input field in versions u… wordfence
33490873-da99-465e-bfb6-44d2ba84f3ee
< 1.0.5
MEDIUM 6.4 The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
334704f8-0854-4eef-bd03-f6ba8d54a3e0
< 1.4.4
MEDIUM 6.4 The Bellows Accordion Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
33398af8-7b7f-47e5-b95b-c9faa33d0c80
< 1.0.86
MEDIUM 6.4 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
3338c56e-6fb5-4962-9eea-7bc1b550570d
< 2.23.3
MEDIUM 6.4 The ArtPlacer Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
33386b7b-fae3-42a4-96d3-df3cdc342317
< 1.9.3
MEDIUM 6.4 The Apollo13 Framework Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho… wordfence
333607d4-ec77-48c2-8f07-14ffbab95fa4
< 1.8.1
MEDIUM 6.4 The ShiftNav – Responsive Mobile Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
3334fc78-48c5-4cfa-ac83-5690fdbf590a
< 1.7.2
MEDIUM 6.4 The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
← Prev 698 699 700 701 702 703 704 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top