๐Ÿ›ก๏ธ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 705 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2ff43e5d-bffd-4e2b-a6de-938559cd6f02
< 2.6.9
MEDIUM 6.4 The WPFunnels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions … wordfence
2fe44e46-dfbf-4286-889c-606280d62218
< 2.3.6
MEDIUM 6.4 The Five Star Restaurant Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the review url pa… wordfence
2fe166a9-8e80-4bb9-8074-5404289f5685
< 5.2.0
MEDIUM 6.4 The ์›Œ๋“œํ”„๋ ˆ์Šค ๊ฒฐ์ œ ์‹ฌํ”ŒํŽ˜์ด โ€“ ์šฐ์ปค๋จธ์Šค ๊ฒฐ์ œ ํ”Œ๋Ÿฌ๊ทธ์ธ plugin for WordPress is vulnerable to Store… wordfence
2fdf2020-ad80-44c3-89b6-fc2ba067cd33
< 3.10.9
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜_idโ€™ param… wordfence
2fc806fe-bf12-4e70-84a2-2027102e5b9b
< 1.7.7
MEDIUM 6.4 The ResponsiveVoice Text To Speech plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sh… wordfence
2fbacaf2-0b3e-4d1e-adc3-c501a6c4c816
< 3.5.0
MEDIUM 6.4 The FunnelKit Funnel Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allow_iframe… wordfence
2fb28dab-1c65-47da-98f7-9eecf5f7466d
< 4.1.6
MEDIUM 6.4 The Smash Balloon Social Post Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in ve… wordfence
2f99da73-1db9-43ee-ac74-b772882baf15 MEDIUM 6.4 The Electric Enquiries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button' parameter of t… wordfence
2f9577c6-7694-45d9-a759-e1f67996b608 MEDIUM 6.4 The WP Mapbox GL JS Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
2f935b4e-31fc-4060-b733-457c4e1b94c8 MEDIUM 6.4 The WP Feature Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0… wordfence
2f8cb7d7-eb40-403e-85de-c16200ee424d
< 4.0.6
MEDIUM 6.4 The CryptX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `cryptx` shortcode in all … wordfence
2f835944-fd27-4f7e-a10d-330fd0fe4ff4
< 3.5.3
MEDIUM 6.4 The WP Table Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting parameter in versions up to, and … wordfence
2f6bfe18-bb9b-4cc2-bdb7-fd9163b61323 MEDIUM 6.4 The Nautic Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'np_marinetraffic_ma… wordfence
2f673be3-04fe-4a42-ae50-9cf4fd5e63d5 MEDIUM 6.4 The Saan World Clock plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in … wordfence
2f66f2ae-af54-4dfa-9cd2-c7ff3a3e865e
< 1.7
MEDIUM 6.4 The Affiliate Ads for Clickbank Products plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bord… wordfence
2f6656e2-35f5-41d8-a330-7904c296ba29 MEDIUM 6.4 The Google Map Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s)… wordfence
2f5b0e3a-037d-42e1-8369-2a74369ec9fc
< 2.7.7
MEDIUM 6.4 The Content Blocks Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
2f5a8f5b-d67c-4c08-9f2d-1f743ffdae81
< 1.1.5
MEDIUM 6.4 The WP Team โ€“ WordPress Team Member Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p… wordfence
2f516d1d-530b-4902-82c5-916478669232 MEDIUM 6.4 The MyWaze plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versio… wordfence
2f4888e1-98b3-48d9-a2d8-416eae447a32 MEDIUM 6.4 The Grey Opaque theme for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜urlโ€™ parameter within the … wordfence
2f335839-73bc-4ede-9d86-6d8ff93cbecc
< 1.5.0
MEDIUM 6.4 The Add infos to the events calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's … wordfence
2f2d1a67-1d9b-4b73-988e-085eaa7474c6
< 2.4
MEDIUM 6.4 The AddFunc Head & Footer Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `aFhfc_head_cod… wordfence
2f1f7414-c399-4f1d-8003-f9899a701c2c
< 1.4
MEDIUM 6.4 The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the H… wordfence
2f1cb71a-aabb-4ba1-93b4-24070aaa582b MEDIUM 6.4 The Years Since โ€“ Timeless Texts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'y… wordfence
2f095368-59e9-4225-9808-96f1be051566
< 5.0.2
MEDIUM 6.4 The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.… wordfence
← Prev 702 703 704 705 706 707 708 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top