πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 714 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
280fdc81-db53-43b6-9675-887d576c4e0a
< 4.8.12
MEDIUM 6.4 The JupiterX Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… wordfence
280a5d6d-192a-43aa-927e-45c50b126463
< 3.24.6
MEDIUM 6.4 The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock_ticker shortco… wordfence
27fc81b0-c03a-4de7-bc38-791401d1685b
< 3.3.53
MEDIUM 6.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'w… wordfence
27f8ff1c-941e-495d-b26e-7eaf765191ef MEDIUM 6.4 The Awesome Wp Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
27dc105c-aada-4cbb-99ec-4e59d2dd7bbf
< 7.3
MEDIUM 6.4 The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
27d6503c-88c1-43b1-82aa-d14705d6bc17
< 1.3.1
MEDIUM 6.4 The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, a… wordfence
27cc6931-086c-43a5-965b-2a19f15bb356
< 2.9.3
MEDIUM 6.4 The ScanCircle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'scancircle' shortcode… wordfence
27be8c38-17f5-4a25-ba53-2a2544f5612a MEDIUM 6.4 The Live Flight Radar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
27b8e0c0-fb0b-4d36-abc4-3e66ec7b5195
< 2.8.4
MEDIUM 6.4 The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor… wordfence
27b2aded-87d4-4127-afd1-5573544d6aaa
< 3.4.2
MEDIUM 6.4 The WP Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.… wordfence
27a48196-60c5-45c4-8d60-c563183fab66 MEDIUM 6.4 The Include Fussball.de Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
27a1f457-6bd9-41eb-83e1-cb9e62950041
< 1.1.3
MEDIUM 6.4 The Easy Demo Importer – A Modern One-Click Demo Import Solution plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
279984d9-f352-467f-a53d-814466d70326
< 2.0.8
MEDIUM 6.4 The Info Cards – Add Text and Media in Card Layouts plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
27988774-3f07-4497-a908-7a42d8bc20cc
< 1.3.11
MEDIUM 6.4 The WP Posts Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
27945f52-7594-46f6-a760-2ee5dd094914 MEDIUM 6.4 The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
277b8437-a215-445c-8257-b0ca3f36336d
< 1.2.78.1
MEDIUM 6.4 The MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. plugin for WordPress is vul… wordfence
2777794d-2c0a-4843-bed8-78e607d4e796 MEDIUM 6.4 The Filestack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'filepicker' shortcode … wordfence
2774e66c-2920-4578-9ab8-20d7dfd6bd6d
< 1.1
MEDIUM 6.4 The Post to Pdf plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gmptp_single_post' s… wordfence
2772cade-c625-437a-b57b-ce8a2e3393bf
< 8.7
MEDIUM 6.4 The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading sh… wordfence
2771f9d4-429f-4691-a65c-073c3a3778fb MEDIUM 6.4 The Mixlr Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mixlr' shortcode in all v… wordfence
276d46c7-0d56-4e32-91fd-9f214bde5447 MEDIUM 6.4 The Spotify Play Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spotify-play … wordfence
2767fcd9-dfc0-4dfa-83d0-b97c59c2cac2
< 2.2.4
MEDIUM 6.4 The CarSpot – Dealership Wordpress Classified Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
27657d29-e834-4f05-8fe9-7db0ab96f67d
< 0.9.30
MEDIUM 6.4 The Microtango plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'restkey' parameter of the mt_r… wordfence
274e5568-b600-4085-8406-9f9d5d4fc35a
< 3.83
MEDIUM 6.4 The Contact Form plugin WordPress is vulnerable to authorization bypass in versions up to, and including, 3.82. This is … wordfence
2731e8ed-27db-4d2b-b76f-8fdccfb2226a MEDIUM 6.4 The PJW Mime Config plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio… wordfence
← Prev 711 712 713 714 715 716 717 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top