πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 719 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
23af50ec-e293-4c06-be64-474057e25845
< 2.2.1
MEDIUM 6.4 The Travelers' Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
23ae17a6-a745-42c4-8627-ad1c41b66e0e
< 2.0.4
MEDIUM 6.4 The MDx theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdx_list_item' shortcode in a… wordfence
23a66e6b-cec0-4110-9bef-a5d41ce1c954
< 5.9.18
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
23a0dcdf-e98f-4e24-9900-49ca522b8038 MEDIUM 6.4 The T(-) Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tminus' shortcode… wordfence
23a081d4-443d-4b3b-8c89-9eb0e23c961e
< 2.7.5
MEDIUM 6.4 The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback,… wordfence
23a01c60-d843-4fc5-a5fa-677f452008b5
< 1.6.51
MEDIUM 6.4 The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site scri… wordfence
23a003fa-b640-499b-b927-03e8ce4fbd62 MEDIUM 6.4 The VoucherPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5… wordfence
23a003aa-d929-4ec3-9d6f-da97222342dc
< 3.3.45
MEDIUM 6.4 The Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via numerous shortcode attribut… wordfence
23953909-4836-4226-b00b-eb0e24cc3ad7
< 1.1.2
MEDIUM 6.4 The WP Dropzone plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'callback' shortcode attribute… wordfence
2389068b-b61d-4598-9a8a-8316a7421907
< 1.1.10
MEDIUM 6.4 The HelloAsso plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.9 … wordfence
2387408b-3017-42c8-8663-3d7d5f858c8a
< 3.2.66
MEDIUM 6.4 The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
237fcdb7-aef9-4d35-baf4-7d382e8b7f3c
< 3.3
MEDIUM 6.4 The Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics plugin for WordPress is vulnerable to Store… wordfence
236eb45e-dfe1-4646-ad19-ba3ec859bb8e MEDIUM 6.4 The Content Manager Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
23623d4c-5859-48f8-b28d-3e3f15bade7d MEDIUM 6.4 The WP BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode in all … wordfence
23554f8a-9df4-483f-a929-4c5d76644cc2
< 1.3.8
MEDIUM 6.4 The Dynamic AJAX Product Filters for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
234a4cd9-4149-4ef0-b543-762a44cce73d
< 1.6
MEDIUM 6.4 The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
2339ee6e-29b6-4c77-b345-cac3569b37a9
< 2.3.13
MEDIUM 6.4 The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.1… wordfence
2321c06c-f4b7-4a70-b8bf-3b3d815b836d MEDIUM 6.4 The Inline Text Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
23106867-372f-424f-a83e-f50b3c47e37a
< 1.2.53
MEDIUM 6.4 The Magical Posts Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
230fbbd0-f6fb-4906-851a-a41b65cdd1c3 MEDIUM 6.4 The Ecover Builder For Dummies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter … wordfence
230f40c1-a8a9-4932-a3f1-ecddc52acca9
< 3.1.26
MEDIUM 6.4 The Icegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.25 d… wordfence
22fa3f61-51c8-47b0-a4af-149491c32573
< 1.3.1
MEDIUM 6.4 The OSM Map Widget for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map … wordfence
22f291eb-d1f8-40d6-b020-f6364164dc40 MEDIUM 6.4 The This-or-That plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'thisorthat' shortco… wordfence
22f05048-df38-4f26-82a3-53caac995283
< 2.1.10
MEDIUM 6.4 The Maxi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `/wp-json/maxi-blocks/v1.0/sty… wordfence
22e4eb2a-2c2b-4f4f-821e-8d2d7e558364
< 3.10.7
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget… wordfence
← Prev 716 717 718 719 720 721 722 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top