🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 721 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
22245bb5-a310-4cd2-98e3-6611e71ff7fa
< 6.0.21
MEDIUM 6.4 The Image Map Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'save_project' function with… wordfence
221c62a8-09c9-405a-bddf-06638437bd39
< 2.5.3.4
MEDIUM 6.4 The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admi… wordfence
221be0f2-61ee-4130-be4a-0df72d3e0197
< 1.7.3
MEDIUM 6.4 The CM Pop-Up Banners for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via campaign data … wordfence
21fed5a3-1bb2-4581-95b4-badff98bed42
< 4.8.9
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of widgets… wordfence
21f8908c-bcfc-4ca1-bc8b-80a80c4a5a4f
< 1.3.12.1
MEDIUM 6.4 The JetBlocks for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple placeholder p… wordfence
21e7658d-b213-4e9c-b3c0-7a84654aa729 MEDIUM 6.4 The Websand Subscription Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
21e12c72-7898-4896-9852-ebb10e5f9a3b
< 5.9.20
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
21df75e6-1f3e-4a08-a620-92b44fb48899 MEDIUM 6.4 The Companion Portfolio – Responsive Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
21d1feae-e70f-439d-8992-f136211fdde0
< 2.7.4.3
MEDIUM 6.4 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
21d0af22-ecce-4533-ba5d-46d6f49fff52
< 1.0.5
MEDIUM 6.4 The Flowerplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘flowplayer6_v… wordfence
21cb424c-4efd-4c12-a08a-6d574f118c28
< 5.1.6
MEDIUM 6.4 The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up… wordfence
21b8fcfe-bdae-414a-a0d2-f20bfd604037
< 1.0.9
MEDIUM 6.4 The “JetWidgets For Elementor” WordPress Plugin before 1.0.9 has several widgets that are vulnerable to stored Cross… wordfence
21a31d61-84eb-47bf-a4d3-e14089127e6c
< 1.3.9
MEDIUM 6.4 The Rich Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes… wordfence
21990e54-c3a2-4bca-b164-132ad456e651
< 2024.4
MEDIUM 6.4 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_iframe_url_as_param… wordfence
219770af-d01e-4ebb-acf5-b4a647a0e16e MEDIUM 6.4 The Bitly plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.4 due … wordfence
217f3595-3c35-46c1-a02c-e8829732a719 MEDIUM 6.4 The Files Download Delay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fddwrap' sh… wordfence
217da4de-38df-41ff-b138-f12d4f8999cd
< 4.6
MEDIUM 6.4 The Simple Popup Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [popup] short… wordfence
217d3148-d411-4fff-a4f6-d5d02ef207af
< 2.6.5
MEDIUM 6.4 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sto… wordfence
21720383-6857-4289-973c-32f2adb8dbec
< 1.2.1
MEDIUM 6.4 The Header Footer Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
21718974-6229-42ee-be71-fbd14be190d2
< 6.2.6
MEDIUM 6.4 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vul… wordfence
21597f22-2690-4a3d-965f-bc99326b7e64
< 1.2.15
MEDIUM 6.4 The Fancy Comments WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's facebook… wordfence
21542a9e-efa2-4655-b076-d282e3678fdf MEDIUM 6.4 The Goods Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
2135a6d4-8d4d-4e2b-8b34-5a07456493ec MEDIUM 6.4 The External Markdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
21341d9c-9f04-4bc6-b9fc-6fa8afd3cf5c
< 1.0.217
MEDIUM 6.4 The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's H… wordfence
21340ccf-eae5-4089-876f-60c3d6510d4a MEDIUM 6.4 The PDF Viewer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
← Prev 718 719 720 721 722 723 724 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top