πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 713 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
28bc0672-3469-4f58-860d-9e13da46804e
< 1.1.0
MEDIUM 6.4 The WP Smart Import : Import any XML File to WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
28ba6f91-c696-4019-ae87-28ebfbe464cf
< 13.4
MEDIUM 6.4 The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'ihrss-… wordfence
28a8f025-c2ab-4a5f-a99e-a2d19b14a190
< 2.88.14
MEDIUM 6.4 The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the map title para… wordfence
28a7b2c9-5d8d-4b49-a47c-473e3288b563
< 18.3
MEDIUM 6.4 The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1… wordfence
28941027-a812-4d53-b3da-4e715202f88d
< 2.06
MEDIUM 6.4 The Sp*tify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
288cd86b-8d13-46bf-99ef-76698cd62a41
< 2.0.3
MEDIUM 6.4 The Robin Image Optimizer – Unlimited Image Optimization & WebP Converter plugin for WordPress is vulnerable to Stored… wordfence
288419ad-fbb2-4a4a-8a40-89ae024e068d
< 2.4.2
MEDIUM 6.4 The CSSIgniter Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' shortcode … wordfence
287bd483-13da-42e9-8fc3-79b800e49582
< 1.9.9
MEDIUM 6.4 The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up… wordfence
287a3f78-ae8c-485a-8a26-77013fe5e9b4
< 2.2.1
MEDIUM 6.4 The Checkout Files Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
2878de45-0123-4e07-bfec-015b36b11d01
< 1.62.0
MEDIUM 6.4 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SiteOri… wordfence
28741ffc-4ff5-4e67-a183-bb5064b6752e
< 4.6.1.1
MEDIUM 6.4 The All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress… wordfence
2873543a-5f81-422e-a0c1-9e2e257c5a6f MEDIUM 6.4 The WP LOL Rotation plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
286c3e26-07a8-4fca-9fdc-98e62ae88b67 MEDIUM 6.4 The Voting Record plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… wordfence
28585718-9678-48a0-bd70-338d9f20bee4
< 8.5.49
MEDIUM 6.4 The VR plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.5.48 due to… wordfence
28548108-a004-4aeb-a0ad-269a73a71331 MEDIUM 6.4 The Five9 Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'toolbar' attribute of the… wordfence
28512684-bf2c-44ac-bb90-82669f2375b8 MEDIUM 6.4 The WP Geo plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.1 due… wordfence
284ea577-ff67-4681-995b-f7bb5ef0ff3e
< 5.9.16
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
284c5646-7728-45bd-9479-483c806ca804 MEDIUM 6.4 The Tabs Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 d… wordfence
2837c9b2-419e-453a-b011-5ec1ef050d62
< 2.4.1
MEDIUM 6.4 The Void Contact Form 7 Widget For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
2828d393-953a-4354-9032-687efda2df33 MEDIUM 6.4 The TinyMCE shortcode Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'btnrel' Shortcode Att… wordfence
28252c89-a2db-441a-93e6-f051f3649fea MEDIUM 6.4 The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up… wordfence
28216197-20b4-4d12-a610-661dca6fbbf2
< 2.0.0
MEDIUM 6.4 The Slickstream: Engagement and Conversions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl… wordfence
281b654a-bb1b-40d6-b912-8cb28e9c35bf MEDIUM 6.4 The Uptime Robot Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
28126b4f-1cb6-4e91-b1c0-09f407d1dbf8
< 1.0.37
MEDIUM 6.4 The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versi… wordfence
28102544-3a33-4f15-af62-714e7dab42b7 MEDIUM 6.4 The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the 'div' attribut… wordfence
← Prev 710 711 712 713 714 715 716 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top