πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 722 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2132d5b4-583d-46c0-be5e-6664bee9cad2
< 2.1.0
MEDIUM 6.4 The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an… wordfence
21322495-a709-45a9-b8df-c3a3aeb1f260 MEDIUM 6.4 The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
2130847a-b6c5-412e-8d90-ba42d3fb21f6
< 3.8.0
MEDIUM 6.4 The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vuln… wordfence
212e33f8-438b-4781-913f-a4f9f6d24a89
< 0.9.2.1
MEDIUM 6.4 The Dropdown multisite selector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's short… wordfence
211a104c-4311-4df9-9083-9cae92ea50b5 MEDIUM 6.4 The Opal Service plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9… wordfence
210fa57c-7cf7-4ff1-84c4-5b3b6bd87a28
< 4.0.3
MEDIUM 6.4 The Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
21065544-8a48-485b-88af-2e638b400de4
< 5.0.5
MEDIUM 6.4 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for Word… wordfence
21019e1f-3d09-4727-8788-281c647d39dc MEDIUM 6.4 The Photo Block – A Modern Image Block With Lightbox and Caption Support plugin for WordPress is vulnerable to Server-… wordfence
2100d720-bfb4-451d-9907-e0b77ef507a5
< 6.7.0
MEDIUM 6.4 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Store… wordfence
2100071c-aa66-445b-acef-7655e64f47e0
< 1.15.8
MEDIUM 6.4 The Interactive Content – H5P plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i… wordfence
20fc675c-08a4-4d77-9872-335d23146906
< 1.2.3.36
MEDIUM 6.4 The Payment Button for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_pay… wordfence
20fb2c18-2502-4d2a-b329-da60070a42ea
< 1.3.7
MEDIUM 6.4 The Meks Flexible Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
20e2454f-f49b-413f-ae45-8b628b30a780 MEDIUM 6.4 The Embed Swagger UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsgui' shortco… wordfence
20daf751-176d-48f2-ac68-480fda89cee1
< 1.6.2
MEDIUM 6.4 The WordPress Pinterest Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gs_pinterest' shortco… wordfence
20d16cc4-3bc2-4f1b-b7ba-17993199a997
< 2.0.21
MEDIUM 6.4 The User profile plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0… wordfence
20cd08ac-826f-40dd-804a-546b0c334b66
< 1.4.15
MEDIUM 6.4 The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
20ba8f45-d101-46e1-b2c3-4f6a588a8fc9
< 1.4.4
MEDIUM 6.4 The Norse Rune Oracle Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
20b3c88f-a0df-4814-83b6-27440c5ad38e MEDIUM 6.4 The Ultra Skype Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_id' parameter of t… wordfence
20b0a946-f429-4615-9d16-4a95a9120c3d
< 4.0.3
MEDIUM 6.4 The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortc… wordfence
20afddaa-5185-4224-a302-2d74461be648
< 1.8.2
MEDIUM 6.4 The Termageddon: Cookie Consent & Privacy Compliance plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… wordfence
20a67cde-612a-4c57-83d6-a5d8f3716a2d
< 2.8.2
MEDIUM 6.4 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
20793de1-468f-4b9d-8e1f-b05dc204c0fb
< 2.8.2
MEDIUM 6.4 The Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms plugin for WordP… wordfence
2070c6e6-d830-4d1c-9408-5cb2254a00e5
< 2.4.30
MEDIUM 6.4 The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnera… wordfence
206d343d-6ed6-461c-bf7d-cf5011ed956f
< 2.1.5
MEDIUM 6.4 The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.… wordfence
206c5736-d9d9-4029-afdf-d76251cc81ac
< 2.6.9.5
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Ca… wordfence
← Prev 719 720 721 722 723 724 725 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top