πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 716 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
26337385-646f-4129-99be-7fa020f67f8e
< 4.10.70
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's link… wordfence
262f7690-97ce-40ca-a277-6871acbc1546
< 1.1.6
MEDIUM 6.4 The HelloAsso plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.… wordfence
2628f9dd-a020-49e6-bcea-f839e1d1a8a0
< 3.1.8
MEDIUM 6.4 Advanced Order Export before 3.1.8 for WooCommerce allows XSS, a different vulnerability than CVE-2020-11727. wordfence
2626ad96-4346-4564-b6bd-0c226bd8dfd4
< 7.8.1
MEDIUM 6.4 The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
26235bfb-4b06-4da9-88eb-dea16d371f16 MEDIUM 6.4 The Photo Swipe plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.… wordfence
2621cb32-3753-42e7-8690-88c680bdf808
< 2.5.10
MEDIUM 6.4 The Paid Memberships Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the edit order page in ve… wordfence
261d280b-60df-407c-9ad5-8fee77ca3070
< 5.15.0
MEDIUM 6.4 The Avada Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.15.0 due to insuffi… wordfence
261bf532-48aa-406f-ba28-2ca3ae919522
< 2.0.10
MEDIUM 6.4 The Goodlayers Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
2618ccde-2bb0-4cd4-b415-68a671507709
< 1.4.5
MEDIUM 6.4 The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking fi… wordfence
2612dab2-a4fc-4434-a107-f2d28f1a1dc8 MEDIUM 6.4 The Hester theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.10 due… wordfence
260c8ee3-dac5-4ad7-ba77-2312160e9348
< 1.10.1
MEDIUM 6.4 The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
260054fd-7cb2-438f-a5ec-0b72338627bc
< 7.8
MEDIUM 6.4 The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SEO Title field p… wordfence
25ff6cc3-02ed-470a-aa10-4843e1ec01ce
< 3.0.0
MEDIUM 6.4 The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'formassembly' sh… wordfence
25fc2600-9b57-405e-9956-b55291161700 MEDIUM 6.4 The iVysilani Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' shortcode attr… wordfence
25f24bdd-0b78-4ec3-821b-6331e5bf65e8
< 2.1.2
MEDIUM 6.4 The ONLYOFFICE DocSpace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'onlyoffice-d… wordfence
25edb9e8-65ea-41d1-a95f-09be110ec1d2
< 4.2.2
MEDIUM 6.4 The Starter Templates β€” Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Stored C… wordfence
25eb1c89-0121-4ea5-a29a-43ec98c468ee MEDIUM 6.4 The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic… wordfence
25ea860e-c4f8-4660-a8cb-aafc4d02bb19
< 5.4.0
MEDIUM 6.4 The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute … wordfence
25e42bf8-794e-46a5-b7db-f1f8802bba00
< 5.6.2
MEDIUM 6.4 The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordP… wordfence
25e11dbd-f751-4dd1-a609-1a5ae7e333b8 MEDIUM 6.4 The wBounce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.1 du… wordfence
25e0be55-ca6d-40c2-972f-fa37c99966c7
< 1.1.12
MEDIUM 6.4 The Custom post type templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
25d6ee47-2a7b-486e-856b-336964b387ae
< 2.8.0
MEDIUM 6.4 The Linear plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linear_block_buy_commissi… wordfence
25d0921b-39b1-4abb-9197-952fc55f80e6 MEDIUM 6.4 The Ungapped Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prefillvalues' parameter… wordfence
25d07a99-d425-4e1a-8adf-d12071552882
< 2.6.2
MEDIUM 6.4 The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cpt' short… wordfence
25cbaa1d-97ff-436d-8a94-c487c05acef9
< 3.0.2
MEDIUM 6.4 The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
← Prev 713 714 715 716 717 718 719 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top