🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 715 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
271a813d-1e20-4a9b-b4d0-6d73cc2866d4 MEDIUM 6.4 The WP Photo Sphere plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
27186143-846a-4e04-bbd2-095caa898617 MEDIUM 6.4 The WP Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.10 d… wordfence
27026f0f-c85e-4409-9973-4b9cb8a90da5
< 5.7
MEDIUM 6.4 The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in version… wordfence
26fe0b7b-dbf8-467f-b5e2-86a858eeaf89 MEDIUM 6.4 The Slider Bootstrap Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'category' and '… wordfence
26e16dd3-66bc-4174-acc1-ee22713ae979
< 3.8.9
MEDIUM 6.4 The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder_i… wordfence
26daa367-ef73-4ae0-843e-6d5366cc4ecd
< 1.2.5a
MEDIUM 6.4 wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly ver… wordfence
26d504fe-38f6-4b50-ae07-c50e35fcb9e0
< 2.2.9
MEDIUM 6.4 An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax… wordfence
26c7be89-a83d-4912-aef5-4cc046b5d768
< 45.0.1
MEDIUM 6.4 The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post/page … wordfence
26c78a0b-63d4-4971-b8d8-a83c975d261b
< 1.9
MEDIUM 6.4 The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Widget Page Title… wordfence
26b5c665-b7f6-4481-b9e9-010f9e451d9b MEDIUM 6.4 The Portfolio Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) … wordfence
26b1b899-37a2-44fd-b961-5e6175e0417f MEDIUM 6.4 The AAWP Obfuscator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-aawp-web' parameter … wordfence
26add730-5421-45c9-9300-230b3da68e1d
< 0.3.3
MEDIUM 6.4 The Code Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.3.… wordfence
26ac377f-c04d-4bc2-9238-3ae5c8d5b8ca
< 3.0.2
MEDIUM 6.4 The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulne… wordfence
26a9bcc5-4057-4cd5-afde-68a2d467c5a9
< 1.3.1
MEDIUM 6.4 The GS Books Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in… wordfence
26a7fb51-f40d-46b8-9f52-495716032a1b
< 3.10.7
MEDIUM 6.4 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
269b9b66-c50f-4171-a8a8-ffb53742b527 MEDIUM 6.4 The OS BXSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6 … wordfence
2697a372-dd88-4532-bbcf-ff5f8dc5a73a
< 1.5.8
MEDIUM 6.4 The Gutenify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.7 d… wordfence
268f2ae1-5360-4ec5-bcd9-dc3ab11396dc
< 1.7.2
MEDIUM 6.4 The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in… wordfence
268c20e4-0c4e-4fc1-867b-0940efe35de1
< 1.5.2
MEDIUM 6.4 The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5… wordfence
268828b2-f660-452f-9d71-74bff3afc333
< 2.31.2
MEDIUM 6.4 The Newspack Campaigns plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
267641fe-7490-4b8f-bb39-9531eefa2c30
< 3.10.2
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link pa… wordfence
26705757-1d3f-4477-b99a-beb229cf36db
< 7.7.2
MEDIUM 6.4 The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable t… wordfence
266507cf-f458-47f8-b18a-81860e6cce3e
< 3.1.5
MEDIUM 6.4 The GS Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
26481723-52f1-4914-bddd-ea175ce885d6 MEDIUM 6.4 The Alemha watermarker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… wordfence
263dd246-32ed-4efc-b7a6-ee6c9d305f89
< 5.6.12
MEDIUM 6.4 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… wordfence
← Prev 712 713 714 715 716 717 718 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top