ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 708 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2d2fc926-6f9f-4ed9-9598-e39b5e6c6544
< 3.9.10
MEDIUM 6.4 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
2d1d9bee-4afa-44cc-8e7a-8a73ad018c4a
< 2.7.6
MEDIUM 6.4 The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback,… wordfence
2d1d8f46-68e4-4101-8ae8-1ca01f5145bf
< 4.7.2
MEDIUM 6.4 The Advanced Coupons for WooCommerce Coupons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
2d13aadf-c144-4919-9bbd-54cb26cf2527 MEDIUM 6.4 The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
2d113191-b550-4752-b536-644206ab56c1
< 3.5.0
MEDIUM 6.4 The BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gute… wordfence
2d092b26-6f36-49db-80fb-968f08af8f62
< 4.2.0
MEDIUM 6.4 The Houzez Theme - Functionality plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 4.2… wordfence
2d07dc6a-a119-478a-9678-45dc580aa863
< 1.0.8
MEDIUM 6.4 The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
2cee1d75-278c-45c6-915d-60aae6a4d3a2 MEDIUM 6.4 The Mmm Unity Loader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributes’ paramete… wordfence
2ce61c74-2754-468b-b40a-5b4446375dfd
< 3.2.26
MEDIUM 6.4 The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Reque… wordfence
2ce0e587-0312-4484-8f03-c82db67aba44
< 4.10.26
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up t… wordfence
2cd82b92-9c8a-4636-ad0b-942dfca372fb MEDIUM 6.4 The Rock Convert plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0… wordfence
2cd364c5-c053-4c50-8232-bb47ab8e834b
< 3.1.2
MEDIUM 6.4 The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all v… wordfence
2ccba77c-fb90-4906-b0fe-77607ec5df1f
< 5.1.14
MEDIUM 6.4 The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner… wordfence
2cc03aa9-ad3d-4abb-9c22-cb40875ece47 MEDIUM 6.4 The WPZOOM Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode… wordfence
2caa5eb7-cde1-4043-bee4-07fa7d76bfd9
< 11.17.1
MEDIUM 6.4 The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Server-Side Request Forgery in version… wordfence
2ca8ab94-45b8-4705-b23b-dbc743572121
< 4.16
MEDIUM 6.4 The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the p… wordfence
2ca1672b-0e4e-4bda-a085-79dab98de820 MEDIUM 6.4 The Page Title Splitter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
2c955905-bf14-4afa-a282-0a8c74cd3b87
< 2.4.44
MEDIUM 6.4 The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Att… wordfence
2c91797c-1e6c-47ab-8a2c-f9aa6120a384
< 2.0.3
MEDIUM 6.4 The Responsive Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
2c8b5f32-7c3f-4e1f-b277-ebe982af5a20
< 3.0.0.2
MEDIUM 6.4 The JetReviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0.0… wordfence
2c648fca-c36f-41a0-9d29-3f669f3669d9 MEDIUM 6.4 The Save as PDF Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's restpackpdfbut… wordfence
2c59179e-2baa-4be2-8415-7fec6dabb24e
< 1.2.5
MEDIUM 6.4 The CM Header and Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
2c557615-148d-43a2-9fed-5f41faa7c64f MEDIUM 6.4 The Listen Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'listen' shortcode in ver… wordfence
2c470cb0-5cbc-4ae1-b75a-384668d07215 MEDIUM 6.4 The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testimonials_g… wordfence
2c38833c-654e-4fe4-b642-ed880a928062
< 5.4.7
MEDIUM 6.4 The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
← Prev 705 706 707 708 709 710 711 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top