🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 706 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2f077817-704f-4595-bfb1-80234dd23f8d
< 2.19.15
MEDIUM 6.4 The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross… wordfence
2ef53c2c-01fb-41b6-b329-d952ce3424e8
< 1.2.7
MEDIUM 6.4 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin fo… wordfence
2ef402a9-b194-444c-9af4-5f79ab573beb
< 3.35
MEDIUM 6.4 The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
2edfceaf-e719-4351-8f5c-2d7dd401c84e
< 5.6.1
MEDIUM 6.4 The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Regi… wordfence
2edc7c4d-598d-4c9c-9aad-ccc97f6a3ac0
< 1.8.6
MEDIUM 6.4 The “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin before 1.8.6 has a widget that is vulner… wordfence
2edabe6d-329f-4b17-b74d-849a0c7c0ef1
< 1.3.9
MEDIUM 6.4 The Black Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
2ed8a7f8-1af3-4b41-bfaf-fd1c35baa867
< 6.24.11.15
MEDIUM 6.4 The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lunaradio' shortcode in… wordfence
2ec6c55d-92c3-4aa0-8baa-746ffdf84ec3 MEDIUM 6.4 The Bible Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 0… wordfence
2ec40d89-9caa-44dc-8577-00fa6463348c
< 1.5.5
MEDIUM 6.4 The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
2ec012e7-b997-466e-8676-8e9467473eae
< 3.7
MEDIUM 6.4 The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
2eaebf25-905c-4a57-96d4-5c3ebbd77b98 MEDIUM 6.4 The My AskAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'myaskai' shortcode in a… wordfence
2e9463de-a9ea-4702-8c46-b2e99b18cef0
< 4.4.12
MEDIUM 6.4 The Image Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.4… wordfence
2e93efec-371c-4050-b24b-e5e978059549 MEDIUM 6.4 The Bootstrap Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho… wordfence
2e936214-ee25-4763-ba7a-b5308cc09a57
< 1.2.4
MEDIUM 6.4 The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPr… wordfence
2e82478c-e476-4cdf-ab72-f578331058e2
< 2.6.9.7
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Member… wordfence
2e81e1ff-1223-4537-8f0f-494658affffc MEDIUM 6.4 The Tooltips plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 10.8.3 … wordfence
2e7d5503-0a6e-4611-bb7c-b2871be828be
< 1.4.5
MEDIUM 6.4 The WPZOOM Portfolio Lite – Filterable Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
2e7afe50-6c62-4c86-8633-f14f8e9412e2 MEDIUM 6.4 The wpPricing Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
2e7aed9e-1b56-4ce6-b338-1d9ab80594c3
< 1.1.9
MEDIUM 6.4 The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widge… wordfence
2e718554-1096-4a16-968d-f00b65e1361d
< 3.6.3
MEDIUM 6.4 The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Motion Text and T… wordfence
2e627cf8-057b-4f1d-b3db-cea8ee63b947 MEDIUM 6.4 The MDC YouTube Downloader plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
2e61489d-a433-4d44-bb12-8c84204922b9
< 1.3.17
MEDIUM 6.4 The Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'event_desc' parameter in all ver… wordfence
2e5fdaae-3ef2-477e-b79b-0b6e415edb40 MEDIUM 6.4 The Posts to Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
2e488a0e-2d60-4f16-9829-d014b0893671
< 2.2.9
MEDIUM 6.4 The Frontend Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
2e32c51d-2d96-4545-956f-64f65c54b33b
< 2024.0
MEDIUM 6.4 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe'… wordfence
← Prev 703 704 705 706 707 708 709 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top