🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 710 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2b8fb88d-4311-41ef-893b-ddd4409c2026 MEDIUM 6.4 The Social Locker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
2b8ad348-80b2-47d8-96d5-a0f043ce0297
< 1.3.3
MEDIUM 6.4 The Themify Event Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
2b81a643-e04a-4e7f-91dd-9241fdd1a3ac
< 2.0.12
MEDIUM 6.4 The Cozy Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.… wordfence
2b77703e-b3d3-4105-a162-0afe86d5b3eb
< 3.4.0
MEDIUM 6.4 The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bump… wordfence
2b747d61-4528-485e-b746-6dddc64485b5
< 3.9.9.5
MEDIUM 6.4 The Eventer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and incl… wordfence
2b654497-ee47-47e9-b88c-7445989896d6
< 2.12.6
MEDIUM 6.4 The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
2b60e693-472e-48ba-81c7-869c9b255762
< 3.5.5.8
MEDIUM 6.4 The Passster – Password Protection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's … wordfence
2b581c4d-a95f-4922-95bb-15f24010ca34 MEDIUM 6.4 The Libsyn Publisher Hub plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
2b290f4c-293d-41d5-b43e-b9c5c350552b
< 1.5.8
MEDIUM 6.4 The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
2b27a7b1-6fee-433f-8102-4a3745a8dfed
< 3.1.1
MEDIUM 6.4 The WZ Followed Posts – Display what visitors are reading plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
2b24ae23-d055-4740-bd86-126d503fce1b
< 3.2.1
MEDIUM 6.4 The TablePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shortcode_debug’ parameter… wordfence
2b1dc849-e306-4c09-a565-14d4e2427c69 MEDIUM 6.4 The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'parent' par… wordfence
2b1b21f4-2130-4b43-bf0b-cb8217770e72 MEDIUM 6.4 The Manual - Documentation, Knowledge Base & Education WordPress theme for WordPress is vulnerable to Stored Cross-Site … wordfence
2b1449a9-6c89-4dec-8107-86cf8a295025
< 5.0.5
MEDIUM 6.4 The Custom post types, Custom Fields & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl… wordfence
2b0cd80c-8bad-46c3-9964-cdacfd4144bd MEDIUM 6.4 The List Pages at Depth plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
2b0bb89c-6c56-4037-8a55-487244e8d519 MEDIUM 6.4 The WP MathJax plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.1… wordfence
2b0ab984-f38c-483d-ab59-1ecadf485e81
< 2.5.2
MEDIUM 6.4 The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
2b0937fe-3ea6-427a-aef7-539c08687abb
< 3.3.1
MEDIUM 6.4 The Theme Switcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'theme_switcha_list… wordfence
2b072278-6627-42b2-a532-c8854c9a4921
< 2.2.4
MEDIUM 6.4 The Post Comments as bbPress Topics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various parame… wordfence
2af82310-fd9a-41b9-9cac-5acb6bcd20be
< 4.15.4
MEDIUM 6.4 The oik plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.15.3 due t… wordfence
2af76ad6-9c78-4b44-b104-d66f0014b5cf MEDIUM 6.4 The Embed PDF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions … wordfence
2af03168-9344-4db0-9b69-2ad1fdb6d472
< 3.9.17
MEDIUM 6.4 The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gu… wordfence
2ad542c9-2025-4875-bd37-f42095c058bd MEDIUM 6.4 The WP-Asambleas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'polls_popup' shortc… wordfence
2ac815c3-db14-4196-9fbd-d5a6c32602f8
< 3.2.4
MEDIUM 6.4 The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
2ac1d65c-5e09-41ca-809b-2ab3ab5f62af
< 5.12.1
MEDIUM 6.4 The Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘settings’ paramet… wordfence
← Prev 707 708 709 710 711 712 713 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top