πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 711 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2ac1168e-51a9-43a2-9086-6b75627bedbf MEDIUM 6.4 The Bg Church Memos plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
2abe953c-dd50-413c-8424-7cd9dbf92d67
< 7.0.0.21
MEDIUM 6.4 The Xagio SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.0.0.… wordfence
2ab4ac58-ea16-4b3b-8646-afe10f331f0c
< 5.4.2
MEDIUM 6.4 The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
2aaca776-03ce-43bb-9553-f455f57124a3
< 10.2.2
MEDIUM 6.4 The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute withi… wordfence
2aa5b7e8-3030-47d3-9440-3b1b5c94b5ec
< 24.0.4
MEDIUM 6.4 The Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
2a90678a-6f40-4f76-9ffb-576827005ec9
< 5.10.0
MEDIUM 6.4 The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.9.1… wordfence
2a804605-c079-4310-a57f-81c3eb216dee MEDIUM 6.4 The NOTICE BOARD plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1… wordfence
2a7f070a-b67c-4e65-a928-a6116266c54d
< 2.11.2
MEDIUM 6.4 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… wordfence
2a6e37c1-aaac-4642-bace-234bbc4f6c38 MEDIUM 6.4 The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … wordfence
2a6bfc87-6135-4d49-baa2-e8e6291148dc
< 5.9.3
MEDIUM 6.4 The Meta Box – WordPress Custom Fields Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
2a5eeae6-313a-4244-9d6a-583828521a3b MEDIUM 6.4 The Shortcode Buddy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all ve… wordfence
2a5ccc0b-a80a-41df-991c-5c356eb10512
< 6.2.1.1
MEDIUM 6.4 The WPJAM Basic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versi… wordfence
2a56b6f1-d3f1-4c6b-9657-a25ebc083b9e
< 3.0.8
MEDIUM 6.4 The Edwiser Bridge plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3… wordfence
2a52f6ae-7cb2-493b-aa99-1d0e1e3cf567 MEDIUM 6.4 The Card flip image slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, a… wordfence
2a521be2-b3ce-47de-8a28-aeff94942d85
< 3.0.4
MEDIUM 6.4 Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers t… wordfence
2a4af494-ef5a-4bcb-916b-d4184d3df9b5
< 3.1.45
MEDIUM 6.4 The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
2a49eb7f-971e-4039-ab2f-5844bf4f2775
< 2.7.11
MEDIUM 6.4 The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,… wordfence
2a295969-454a-47fb-bc35-4e84db38c887
< 2.3.0
MEDIUM 6.4 The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortc… wordfence
2a275deb-a0e3-491a-bed6-9f6112918061 MEDIUM 6.4 The Social Feed Gallery Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' paramet… wordfence
2a225ccb-a7dc-4437-bd97-b309d6ae6a47
< 5.9.10
MEDIUM 6.4 WordPress Core is vulnerable to Stored Cross-Site Scripting via the Template Part Block in various versions up to 6.5.5 … wordfence
2a203577-0ced-4e1e-a7db-e4ca53a5bade MEDIUM 6.4 The Unique theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 0.3.0 … wordfence
2a090167-0ea9-47f9-be8f-fe392da9ec38
< 2.2.1
MEDIUM 6.4 The Embed Google Photos album plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a… wordfence
29ef6956-aeb7-4a72-9f51-b5c5b05c1425 MEDIUM 6.4 The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt… wordfence
29e9ad80-6a02-494a-9d53-0f14728952aa MEDIUM 6.4 The Outgrow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the 'outgrow' sh… wordfence
29de27d3-e9f5-4e73-8b6d-4491d2151d7f
< 1.1.0
MEDIUM 6.4 The Awesome Progress Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
← Prev 708 709 710 711 712 713 714 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top