🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 709 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2c251bf5-f6c0-4d2e-a240-95b0f1fce3f5 MEDIUM 6.4 The GMAPS for WPBakery Page Builder Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
2c1ecd71-57ed-44ba-a007-3b96b98d3bf7
< 1.5.3
MEDIUM 6.4 The CM Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cmbd_featu… wordfence
2c07b5c8-7fae-499d-9f6c-9392166f74b8
< 3.8.3
MEDIUM 6.4 The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p… wordfence
2bffed25-d7f0-40de-a55d-42653aff0673
< 1.3.2
MEDIUM 6.4 The WP-WebAuthn plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.… wordfence
2bf70203-61c0-406a-9110-b60761b4a513
< 1.0.6
MEDIUM 6.4 The pdfl.io plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pdflio' shortcode in all versions… wordfence
2bf511b6-1b62-43e0-9df5-674a423f6ae2
< 1.6.2
MEDIUM 6.4 The Testimonial Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blockip’ paramete… wordfence
2bed4818-70c5-40b7-8d8d-f43f3baa0f3d
< 2.3.5
MEDIUM 6.4 The LightPress Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `group` attribute in t… wordfence
2be1fbfc-a809-4a42-9be4-24c8274c1e71
< 1.8.15
MEDIUM 6.4 The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's babe-search-fo… wordfence
2be16ee8-6bae-44d9-bde7-8e893293c3f9
< 1.0.7
MEDIUM 6.4 The WOLF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wpbe_update_page_field parameter in v… wordfence
2be089a0-d4d5-4d64-8fb7-8c42286ebbcd
< 3.7.30
MEDIUM 6.4 WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled. wordfence
2be06087-4616-47bb-8a33-3bba97c47cb2
< 3.5.37
MEDIUM 6.4 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
2bde5862-1b7c-4e58-b13f-c8f347593c51
< 2.26.9
MEDIUM 6.4 The IP2Location Country Blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameter… wordfence
2bd989c7-b7dc-4243-83ae-23621d100052
< 7.4.0
MEDIUM 6.4 The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
2bd6b66d-f33e-4287-850b-a199de72f6ad
< 5.4.1
MEDIUM 6.4 The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all ver… wordfence
2bd53172-ddfa-481a-818d-626b9db6fe41
< 2.6.9.3
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid W… wordfence
2bcc2783-1c47-47e4-ba63-822012aba0a6
< 1.4.46
MEDIUM 6.4 The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Sho… wordfence
2bc8a3fb-176e-4bf0-b96e-6ccb9688254b
< 1.1.9
MEDIUM 6.4 The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Stor… wordfence
2bc0b654-5174-41bc-9e8a-40257ceb7ded
< 1.2.2
MEDIUM 6.4 The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag… wordfence
2bbe86c8-d568-49e2-bf3f-830c1dd53dec
< 5.0.18
MEDIUM 6.4 The Ninja Tables Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
2bb15304-1e46-44c6-b21b-e6768b79240a
< 2.2.100
MEDIUM 6.4 The Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.99… wordfence
2ba55591-f4f3-4e90-9358-ca9c7ca01b09
< 4.0.0
MEDIUM 6.4 The MapifyLite and MapifyPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
2b9c4ca8-e5cd-4c4f-8d81-b06367c89fd7
< 2026.2
MEDIUM 6.4 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in … wordfence
2b9b501e-2ce7-43d8-bad2-6c3176eed8e2 MEDIUM 6.4 The PayMaster for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a… wordfence
2b9999f4-6bff-4658-ad58-7707e0d22ccc MEDIUM 6.4 The WordPress Events Calendar Plugin – connectDaily plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
2b95b72e-b986-4492-9537-74fecf5e93a8
< 1.3.7
MEDIUM 6.4 The Black Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
← Prev 706 707 708 709 710 711 712 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top