πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 707 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2e28daa5-cdbb-464c-99d5-09a924c01b41
< 8.12.1
MEDIUM 6.4 The MonsterInsights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unspecified block options (use… wordfence
2e1d1283-3bd9-458e-81ca-9934b293415a
< 1.2.5
MEDIUM 6.4 The Lenxel Core for Lenxel(LNX) LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploa… wordfence
2e0cde65-f75c-4602-bffe-97b391a428b4
< 3.2.39
MEDIUM 6.4 The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-… wordfence
2df53b60-c524-4ebd-9a99-ef8e14c140c7 MEDIUM 6.4 The Bootstrap Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `box` shortcode in all… wordfence
2de2d2c5-1373-45b6-93a0-575713226669 MEDIUM 6.4 The WordPress Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wp_charts' shortcode in vers… wordfence
2de2624a-3f39-4060-b41c-95a0c114b55c
< 5.12.1.1
MEDIUM 6.4 The TheGem Theme Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.12.1.1 d… wordfence
2de22728-4f67-406c-9db5-33cbba4c15eb
< 1.3.6
MEDIUM 6.4 The IMS Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown post settings in a… wordfence
2dd5c257-8bf4-44bf-8d76-f3f339ed852c
< 3.5.2
MEDIUM 6.4 The Additional Custom Emails & Recipients for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
2dbed00f-d971-4673-95b7-950a25f0ba7b MEDIUM 6.4 The WPLMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.9.5.4 … wordfence
2db0f9b6-fa03-4dea-b47d-ea070e6d1c4c MEDIUM 6.4 TheSuperlist - Directory WordPress Theme | Directory & Listings theme for WordPress is vulnerable to Stored Cross-Site S… wordfence
2dae9e8f-6f07-498d-98dd-487f8df8ada9
< 1.6.1
MEDIUM 6.4 The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
2dae6b53-11f3-432c-ad27-940c429055a2
< 4.5.6
MEDIUM 6.4 An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not… wordfence
2daddb7a-0ea7-4d11-8699-1982e336120f
< 2.2.12
MEDIUM 6.4 The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPre… wordfence
2da32063-3763-46b5-86ac-91883f9c809b
< 5.1.1
MEDIUM 6.4 Multiple plugins for WordPress by by eMarket Design are vulnerable to Stored Cross-Site Scripting in various versions du… wordfence
2da2c677-505c-4d7f-aaee-89dd8645be2d
< 1.3.3
MEDIUM 6.4 The News Ticker Widget for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
2d9c4d9d-5d4c-4ea9-bf8d-0ee634f9ca7c
< 2.0
MEDIUM 6.4 The Stylish Order Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'product_name' … wordfence
2d90737b-fc4b-45a3-b970-64468e9eb431
< 1.2.9
MEDIUM 6.4 The Support Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
2d8d7a10-8086-48f7-af6f-6abfe7767fbc
< 5.6.0
MEDIUM 6.4 The Custom Query Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
2d581a38-736a-497f-aaf7-6da0b2421618
< 3.8
MEDIUM 6.4 The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p… wordfence
2d4abd91-f241-4a40-b164-e0f8a4f13d1a
< 0.19.1
MEDIUM 6.4 The Theater for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
2d45afd4-9a1f-402c-86e3-8e3d6d7178d3
< 3.2.5
MEDIUM 6.4 The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPres… wordfence
2d4225a6-4aae-49a5-93e1-8dcc9a77e089
< 1.7.1050
MEDIUM 6.4 The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' p… wordfence
2d3c2f4b-389e-4dec-bb18-b63cfa053947 MEDIUM 6.4 The WP Easy FAQs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's WP_EASY_FAQ shortcod… wordfence
2d34f957-e6e3-4b16-9d59-d481eec429eb
< 3.4.8
MEDIUM 6.4 The Interactive World Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
2d3188c2-e5b0-4d83-8c92-ae6b409c92f9
< 5.9.3.3
MEDIUM 6.4 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
← Prev 704 705 706 707 708 709 710 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top