πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 703 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
31f4bad5-3a11-42c6-a336-6bd178ab5113
< 3.4.18
MEDIUM 6.4 The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
31f05d67-e963-4108-a276-fa024b174101
< 3.6.1
MEDIUM 6.4 The Ohio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.0… wordfence
31e8c399-f8d3-461c-98fa-04f8cbb82d12
< 6.4.12
MEDIUM 6.4 The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for W… wordfence
31e5e799-17cf-41a9-aa99-b29dec529579
< 2.2.0
MEDIUM 6.4 The Enter Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1… wordfence
31dfd1d2-9e09-45b3-b018-6ce12a981298
< 1.0.6
MEDIUM 6.4 The Business Card Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
31d6288d-87f0-4822-b3f4-541f70cf99fd
< 2.0.4
MEDIUM 6.4 The flowpaper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'flipbook' shortcode in versions up … wordfence
31cb7a9d-8965-49cd-b1fb-0d141038a0e1 MEDIUM 6.4 The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
31b80508-11cf-4508-a3ef-95b5da4fb81b MEDIUM 6.4 The Shuttle theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.0 due… wordfence
31b52500-c53c-4606-b57c-cd14bb66afa9
< 3.5
MEDIUM 6.4 The JobCareer | Job Board Responsive plugin for WordPress is vulnerable to both authenticated Stored and unauthenticated… wordfence
31a145d5-3c0c-436f-a1ee-afff14ef2140 MEDIUM 6.4 The Art Direction plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.… wordfence
3173b995-98ba-47f2-afb3-bbd2949f1d8e
< 1.3.16.1
MEDIUM 6.4 The JetBlocks For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
316ffb37-47fe-47c4-8a81-5794fa12ce33
< 2.0.3
MEDIUM 6.4 The salient-core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all … wordfence
316a1ca9-e5fd-463f-ba1e-32589740270a
< 2.4.4
MEDIUM 6.4 The HT Mega plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.3 du… wordfence
315687d4-9125-440b-9d53-81d71e56d4ef MEDIUM 6.4 The Elastik Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all v… wordfence
31522e54-f260-46d0-8d57-2d46af7d3450
< 2.7.2
MEDIUM 6.4 The Bitly's plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpbitly' shortcode in al… wordfence
313d2749-7662-4870-b0f7-19253797f833 MEDIUM 6.4 The Ad Short plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ad' shortcode's 'client' attribu… wordfence
313613ea-18cf-4e7d-aa75-586b80752edb
< 2.7.0
MEDIUM 6.4 The Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates plugin for WordPress is vulnerab… wordfence
312dabb0-9ae8-41a0-80b3-f4962c8066de MEDIUM 6.4 The Funnelforms Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
3121bb03-7bc0-4005-9814-bc46ce9d4a9d MEDIUM 6.4 The QuestionPro Surveys plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'questionpro' shortcod… wordfence
3120a964-223c-458d-93ce-1a9322772166
< 1.7
MEDIUM 6.4 The WP DPE-GES plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6 d… wordfence
3118b34e-d3e2-4a90-9a0f-e6cf71348dd1
< 1.7.4
MEDIUM 6.4 The Responsive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
31189328-3dba-4bc4-a541-ef53bbf9794f MEDIUM 6.4 The StoryMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1 due… wordfence
3115e8ad-8e68-41e9-a3a0-5f003d921037
< 4.5
MEDIUM 6.4 The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPre… wordfence
3111d016-e414-44df-925a-84010316c4ff
< 4.9.0
MEDIUM 6.4 The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
30f66c86-5bc6-46bd-b883-3f61bcd6b176
< 3.6
MEDIUM 6.4 The Yada Wiki plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5 du… wordfence
← Prev 700 701 702 703 704 705 706 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top