πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 704 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
30f3a208-ffe0-4d87-9c76-91451f7a1591
< 4.6
MEDIUM 6.4 The DSGVO All in one for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
30e32736-6f51-4cae-894e-db792b83afe6
< 2.0.13
MEDIUM 6.4 The WP Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
30e0bf40-7f7b-43e6-8439-6dc00a889344
< 2.1.2
MEDIUM 6.4 The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… wordfence
30d79f14-b70c-403b-9e55-66e40b18aca7 MEDIUM 6.4 The WP Responsive Meet The Team plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wprm_team' sh… wordfence
30d39718-945a-43a2-be08-70be1af55965 MEDIUM 6.4 The GmapsMania plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's gmap shortcode in all … wordfence
30d127b1-3d8d-4e77-90a8-a24e7b93fe16
< 2.1.1
MEDIUM 6.4 The Himer theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.… wordfence
30cb1b8c-84ce-4401-9c30-775efb257fe6
< 1.1.9
MEDIUM 6.4 The Testimonial Slider Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attribu… wordfence
30c9c4b9-6905-4d8a-bc55-5cd6f6201d25
< 7.7
MEDIUM 6.4 The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' short… wordfence
30bfa616-c7f3-4ff0-85b3-468debc8a73e
< 0.13.21
MEDIUM 6.4 The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜_wp_attachment_… wordfence
30a6d334-3838-4ed4-b688-c3887d9091c0 MEDIUM 6.4 The Sports Club Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before' and 'after… wordfence
30a1517e-5ea5-47a1-afe8-9543e1ffd199 MEDIUM 6.4 The 012 Ps Multi Languages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via translated titles in al… wordfence
309eb1df-728f-404d-a20d-a83a0ab8ed0c
< 4.1.4
MEDIUM 6.4 The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all v… wordfence
3084c9ab-00aa-4b8e-aa46-bd70b335ec77
< 3.3.1
MEDIUM 6.4 The Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and … wordfence
3077b84e-87af-4307-83c5-0e4b15d07ff1
< 1.3.0
MEDIUM 6.4 The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Stored … wordfence
30670489-2db2-4c55-b46f-4818f2608ca9
< 3.3.2
MEDIUM 6.4 The Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
305fc4a9-8b22-49ef-84eb-062986dbcf58
< 1.1.1
MEDIUM 6.4 The Display Remote Posts Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, … wordfence
30579058-54f4-4496-9275-078faf99823f
< 5.4.2
MEDIUM 6.4 The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and … wordfence
30438a21-9361-4797-83f3-f832234a6cb5
< 1.6.3
MEDIUM 6.4 The MediaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.2… wordfence
30433ffa-ab1d-4f7c-b7ca-9a5eeafb581f MEDIUM 6.4 The Tabs Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all … wordfence
3041e28e-d965-4672-ab10-8b1f3d874f19 MEDIUM 6.4 The EasyRotator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyro… wordfence
30339c0d-6632-4073-b4d5-3bb4a5b8a58d
< 1.1.8
MEDIUM 6.4 The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all ve… wordfence
3011befd-c0c6-4800-a370-e592c3ec483f
< 2.1.8
MEDIUM 6.4 The Nova Blocks by Pixelgrade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribut… wordfence
3011b783-e4b4-45d2-81af-2f8d166a30ac
< 2.6.9.4
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribu… wordfence
300b24af-10a1-45b9-87ec-7c98dc94e76b
< 1.0.240
MEDIUM 6.4 The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's extend_build… wordfence
3005c53e-eb09-479f-a4e4-b8d40583d80d
< 3.2
MEDIUM 6.4 The Resume Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3… wordfence
← Prev 701 702 703 704 705 706 707 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top