🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 717 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
25afc28c-2814-4b49-add5-1d0ce5ff3a07
< 2.0.9
MEDIUM 6.4 The Taxonomy Chain Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pn_chain_menu… wordfence
25a3bba1-99e4-45ec-b761-fa1282948516 MEDIUM 6.4 The Simple Business Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
259d7b97-23a9-445b-a8dd-a384526bef47
< 3.20.7
MEDIUM 6.4 The Markup Markdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
258a2d5d-a176-4b89-bc4c-089d072982dd MEDIUM 6.4 The AudioTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' shortcode attribute of… wordfence
257da138-8a1c-4c4c-a0e1-04eed4541bdb MEDIUM 6.4 The Stagtools plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.8 … wordfence
257c47d4-811c-49ce-8d56-a595bc2aa26e
< 2.1.2
MEDIUM 6.4 The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' attribute of th… wordfence
256b4818-290b-4660-8e83-c18b068a8959
< 1.3.88
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via element U… wordfence
2561ad0f-26b9-4581-8a52-76b69db80d6f
< 3.7.0.2
MEDIUM 6.4 The Uncanny Toolkit for LearnDash plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
25554434-2330-4c58-8764-109e12065659 MEDIUM 6.4 The CRM 2go plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 due … wordfence
254f3a1c-0d5d-499b-9da7-129f21ba70af
< 2.9.13
MEDIUM 6.4 The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Premium Magic Scroll mo… wordfence
25462492-59d2-44b7-81c3-93ac04a08bcc
< 6.0.4
MEDIUM 6.4 The Enfold - Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘… wordfence
2540bd75-ba5e-4aaf-9e65-8fc22c8b87cf
< 2.3
MEDIUM 6.4 The Social Media Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acx_widget_si_theme',… wordfence
25302010-202a-458e-93b6-2e6b8604c091 MEDIUM 6.4 The Wp chart generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpchart shortc… wordfence
250edcf8-b56e-4714-9207-25bab2adaf9c
< 2.5
MEDIUM 6.4 The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blockip’ parameter in ver… wordfence
250ce6a5-d479-419b-b2b0-306895f2b782 MEDIUM 6.4 The JSM file_get_contents() Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
250b8588-5f5c-41c1-b866-a1233a7f8910 MEDIUM 6.4 The Include URL plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.3.… wordfence
2508adc4-2a2f-4b6c-9b5a-da85d94226a0
< 1.2.11
MEDIUM 6.4 WordPress Fancy Comments Plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
24f6c4e4-11c3-476f-9f50-42053b625ab8
< 2.8.0
MEDIUM 6.4 The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Price Ran… wordfence
24ebaf12-cf7c-4bc3-b028-27ee4b6b2a45
< 7.5.44.7212
MEDIUM 6.4 The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
24df10fb-5143-478e-90f0-27f604ad43ee
< 1.0.236
MEDIUM 6.4 The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
24ce9ae1-da02-4ef1-aeb5-1f6b98f41f5a MEDIUM 6.4 The Custom Admin Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
24ba85a0-dbc7-4c9d-a67f-d449c1d275ab
< 6.3
MEDIUM 6.4 The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter fou… wordfence
24b9bf5a-19ac-4e99-b32d-1ab681356a1b MEDIUM 6.4 The Livemesh Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cro… wordfence
24b89ed2-9dfb-4068-8459-cb2e708c7778
< 3.7.11
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated us… wordfence
24b3423b-66df-46ad-ae92-20e7ffbd1614
< 1.8.3
MEDIUM 6.4 The Salient Portfolio theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
← Prev 714 715 716 717 718 719 720 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top