πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 718 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
24b26f17-f973-4a0e-85e2-a70a394246e2 MEDIUM 6.4 The Schedulicity - Easy Online Scheduling plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
24a33857-5df2-4747-950e-f5a87fd287c6
< 1.2
MEDIUM 6.4 The HostFact bestelformulier integratie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… wordfence
249acca6-49b4-4ddf-af75-31f68921fc19
< 5.9.6
MEDIUM 6.4 The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper … wordfence
248a9cb2-24e8-46b2-9ef8-23a8444a922d
< 2.2.88
MEDIUM 6.4 The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
247f6b86-767b-479f-90d4-79345699dd59
< 7.2.0
MEDIUM 6.4 The MonsterInsights – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
247e252a-ac4f-4567-813b-1ceb8b5f6a22 MEDIUM 6.4 The Giveaways and Contests by PromoSimple plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
246e227f-a22d-43bb-8bd0-63d9b4803f26
< 1.5.1
MEDIUM 6.4 The Hash Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
246dee15-82e0-4630-8d95-d2419e9eaef8
< 3.4.1
MEDIUM 6.4 The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… wordfence
246bf014-c52b-4d5d-b80a-7f3345aaa47a
< 1.3.18
MEDIUM 6.4 The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
245d909e-7efe-4467-96e2-143efced4ffe MEDIUM 6.4 The TradeMe widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
24486605-9324-4f19-9ca3-340d006432db MEDIUM 6.4 The Page Builder by AZEXO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'azh_post' shortcode in … wordfence
24120d7f-e382-45d5-aeab-bc302415c1f1 MEDIUM 6.4 The Utech World Time plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
240fbd3b-3daf-415e-9551-76e3909508da MEDIUM 6.4 The Category D3 Tree plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
240bf16c-2535-45ae-939b-e288225a3082
< 2.3.1
MEDIUM 6.4 The Donation Block For PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
23ff12f0-eb9d-4bb3-8db0-0e794c0f0594
< 7.8
MEDIUM 6.4 The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜link’ parame… wordfence
23f1b1da-2ac0-49c1-bb32-2fe2cfd56192
< 2.2
MEDIUM 6.4 The Real Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
23ee5d94-5a51-4ee3-945c-422f3f07634e MEDIUM 6.4 The Recencio Book Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
23ea062b-9d9f-4db0-9263-95bacf7def73
< 5.5.9
MEDIUM 6.4 The Coins MarketCap plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
23e39019-c322-4027-84f2-faabd9ca4983
< 2.10.27
MEDIUM 6.4 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fie… wordfence
23e1fffa-9170-4bc2-ad7e-27708a08033b
< 3.16.6
MEDIUM 6.4 The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin… wordfence
23cdd891-bfa0-472c-b99f-5aac45202bc8 MEDIUM 6.4 The News Element Elementor Blog Magazine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
23ca6846-83b7-4daa-b17b-6ca8c758dbb0 MEDIUM 6.4 The WP SimpleWeather plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
23b75226-e7c9-4b22-aa1b-1a7d400856d2
< 4.0.0
MEDIUM 6.4 The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Membe… wordfence
23b3570c-cd8e-4dec-bbad-6374c44530bd
< 3.1.1
MEDIUM 6.4 The MK Google Directions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MKGD' short… wordfence
23b2fc40-d8e3-4b84-ab8d-ff82a6f21842
< 4.5
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to… wordfence
← Prev 715 716 717 718 719 720 721 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top