ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 712 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
29cc82cb-f3fd-4de5-9731-7ceb1212b0f9
< 2.1.6
MEDIUM 6.4 The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
29b1984d-e6da-49d5-8b40-cdf2f1bcc1bb
< 3.3.3.2
MEDIUM 6.4 The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attribut… wordfence
29a39cd9-a190-40b3-897d-c7a6ac781605 MEDIUM 6.4 The Nite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
29a160ea-5582-4028-8621-7988e3a8cabf
< 0.16.8
MEDIUM 6.4 The AnWP Football Leagues plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all … wordfence
2990a3ba-3dad-4204-bccc-ed5c23d9d581 MEDIUM 6.4 The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
2970ea7e-bd36-4b43-bc55-bc545efbeb67
< 4.5.5
MEDIUM 6.4 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
2970bea4-4641-4885-b996-2bf0b848e1ec
< 1.4.1
MEDIUM 6.4 The Exchange Rates Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
29640c6c-cebb-48ec-b7e6-044d0426d015
< 8.4
MEDIUM 6.4 The Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… wordfence
2961d6ef-f039-45dd-b47e-8b85c409668c MEDIUM 6.4 The Twitter Bootstrap Collapse aka Accordian Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
295f7b2a-bc41-4a24-bde1-47d53237d6d0
< 2.1.18
MEDIUM 6.4 The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
29590e8b-dd4d-48e8-b374-4dbfb33ebe8c
< 2.2.2
MEDIUM 6.4 The Sitewide Discount for WooCommerce: Apply Discount to All Products plugin for WordPress is vulnerable to Stored Cross… wordfence
2950a264-b60c-48ad-b8e0-6d0e1a230982
< 1.14.14
MEDIUM 6.4 The Pay with Vipps for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the buy now but… wordfence
294b5bd1-a7c8-4c06-b107-e80bf3b35da8
< 2.1.7
MEDIUM 6.4 The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
2947a6e9-e357-4751-adfd-f9043bef75e9
< 0.24
MEDIUM 6.4 The Embed Bokun plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all v… wordfence
293abae5-a7fb-401f-af09-324a81ce8709
< 4.16
MEDIUM 6.4 The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the… wordfence
291629c3-1c28-4abb-af1f-56942fe6f475
< 6.0.3
MEDIUM 6.4 The WP Ticket Customer Service Software & Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
291205ac-b161-4694-93af-f3fc96e0ea02 MEDIUM 6.4 The Course Booking Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
290e9d95-0dac-4cc8-8cef-9e7974405f36
< 2.5.0
MEDIUM 6.4 The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's oceanwp_library short… wordfence
290a790f-7d11-4be7-9146-cb07919b1e60 MEDIUM 6.4 The Easy Plugin Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eps' shortcode… wordfence
2904e3dd-2a5f-49f2-a949-e76c4ccfc54c
< 3.20.6
MEDIUM 6.4 The Flatsome theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.20.5 d… wordfence
2901761c-426a-4f06-84db-247c70a3784d
< 2.0.19
MEDIUM 6.4 The Cozy Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.… wordfence
28e75881-578b-41c3-946b-ef19edb8f067 MEDIUM 6.4 The GTDB Guitar Tuners plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
28d6a36b-ba8b-4c73-9e89-0fb85353b58e
< 2.5.12
MEDIUM 6.4 The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
28ca388f-0505-47ae-9408-e3d101101fae MEDIUM 6.4 The Oi Yandex.Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shor… wordfence
28bdaf44-6f2c-440a-a96f-bdcd71fb7bea MEDIUM 6.4 The WP Cleanup and Basic Functions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File upload… wordfence
← Prev 709 710 711 712 713 714 715 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top