🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 720 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
22e09431-dd71-4a90-84ba-4b676ec8ccb3
< 1.1.5
MEDIUM 6.4 The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
22d9ccd6-24fb-4863-b5ac-b22b9958007b
< 4.4.5
MEDIUM 6.4 The Church Admin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,… wordfence
22d8847d-f73f-40ad-8b8c-8e602d226be5
< 3.2.1
MEDIUM 6.4 The Blockspare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the latest post block in versions u… wordfence
22d222e8-adbc-4217-a820-e9196521fd03 MEDIUM 6.4 The Foundation Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
22d1ccf3-ac1a-4dfc-81c3-b8eb88795bc1
< 2.0.43
MEDIUM 6.4 The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tagName’ parameter in versions… wordfence
22c63226-2bc6-40be-a5d1-1bd169fc78b8 MEDIUM 6.4 The Slick Contact Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcscf-link' shortcode in … wordfence
22c4b981-6135-4c44-aa68-f0d51704a68c
< 2.7.18
MEDIUM 6.4 The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the *_html_tag*… wordfence
22c2b12b-dc80-4127-86bd-21d4f1988e56
< 3.1.3
MEDIUM 6.4 The Neve PRO theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.2 du… wordfence
22bf2719-335d-4331-8c59-648f6f903ffa
< 3.0.5
MEDIUM 6.4 Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject… wordfence
22ba0eaf-f514-420a-9680-8126f6dcdde9
< 4.0.18
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Link… wordfence
22b59b36-ba47-4c10-8f43-a29ae3b9d446
< 6.7.19
MEDIUM 6.4 The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all vers… wordfence
22b2a290-36ea-45ba-b43d-6820247121fa
< 6.3.0
MEDIUM 6.4 The PDF for WPForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
22a79d2b-44f8-406d-baea-8bfba291b462
< 5.9.0
MEDIUM 6.4 The Lightbox with PhotoSwipe plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
22a4b2b3-16f5-49b9-ac15-7abe903eac5f
< 2.8.7
MEDIUM 6.4 The Ultimate Store Kit Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
22a30301-f409-4c53-84d7-7799fb41c25b MEDIUM 6.4 The Live Stream Badger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livestream' s… wordfence
22a02e75-4ab1-48fb-b618-b1dff2fcd97f
< 2.7.7
MEDIUM 6.4 The NewsmanApp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'newsman_subscribe_wid… wordfence
229e3e0e-daf4-4ed0-93c3-46a65efc52d1
< 2.6.4.1
MEDIUM 6.4 The Namaste! LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6… wordfence
229c88ea-c091-43b6-ac4d-31bccdd13a07
< 4.0.2
MEDIUM 6.4 The WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ paramet… wordfence
229a4e61-571c-44c6-9972-4dfc743afffe
< 2.12.0
MEDIUM 6.4 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… wordfence
228fab65-e5c2-41d1-ad41-fac4862894f2
< 2.2.2
MEDIUM 6.4 The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
228763ff-e6b0-4bba-b74f-50652e32c050 MEDIUM 6.4 The wp-pano plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.17 due… wordfence
226baf3e-1b28-4196-9438-0b17fef4c5af
< 1.2.0
MEDIUM 6.4 The 코드엠샵 소셜톡 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's add_plus_f… wordfence
224a9234-2cf3-48ca-878e-3d7207629beb
< 9.8.0
MEDIUM 6.4 The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title & Descr… wordfence
2244945a-5b3a-463d-9910-46a6f7afaf6c
< 4.4.7
MEDIUM 6.4 The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restri… wordfence
222fab17-65bf-43af-9a42-475fd2643a69
< 3.4.9
MEDIUM 6.4 The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored… wordfence
← Prev 717 718 719 720 721 722 723 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top