🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 724 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1f9277d8-ac81-4950-a1e5-4e6c6b042f84
< 1.2.2
MEDIUM 6.4 The BNE Gallery Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' sh… wordfence
1f8fd161-4a26-4b02-abe8-f0b7eac22a48 MEDIUM 6.4 The Next Page, Not Next Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
1f784dfa-5c31-4c44-9230-7beac7f56893
< 3.3.6
MEDIUM 6.4 The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘con… wordfence
1f645d0c-d641-4fff-a4f4-33c037de30e9
< 5.0.33
MEDIUM 6.4 The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchno… wordfence
1f63287f-cf9f-486c-b0fc-20302601e241 MEDIUM 6.4 The C9 Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.7 … wordfence
1f5c3b2c-1ed2-47e1-8e39-cbe6f2973d15
< 11.7.0
MEDIUM 6.4 The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple pa… wordfence
1f5390b1-c85b-4bf6-ab38-6ae0efe72ffa
< 3.0.7
MEDIUM 6.4 The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field'… wordfence
1f463ed1-06ad-430f-b450-1a73dc54f8a7
< 9.1.1
MEDIUM 6.4 The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in a… wordfence
1f413fc2-8543-4478-987d-d983581027bf
< 3.5.0
MEDIUM 6.4 The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Settings user profile fields i… wordfence
1f41101c-c54f-4e97-a0fb-79a17d5f0929
< 3.21.1
MEDIUM 6.4 The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to… wordfence
1f39c2db-cf9a-4abf-bb43-f7e860b656d4
< 1.9.8
MEDIUM 6.4 The Create by Mediavine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
1f386d27-8aae-4f18-9311-3dd018ea1c85
< 2.2.3
MEDIUM 6.4 The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
1f35fd20-a5ff-40e3-8af0-df3876c41ef8 MEDIUM 6.4 The Chartbeat plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.… wordfence
1f22cb85-2abc-43ab-9f83-c304d618c7d9 MEDIUM 6.4 The GDReseller plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6 d… wordfence
1f2135ab-ef76-4539-81ad-51abc4e051ce
< 4.3.5
MEDIUM 6.4 The Gratisfaction plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… wordfence
1f18147d-60e6-447d-a6f5-6ad7b633e62c
< 1.0.6.1
MEDIUM 6.4 The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is v… wordfence
1f04fa24-95e3-4480-858e-9101ecae05e3 MEDIUM 6.4 The Smart SEO Tool – SEO优化插件 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
1ef93096-ee09-4ea2-b299-3e173d731b8b
< 2.0.0
MEDIUM 6.4 The Responsive Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
1ed075f2-778a-49f5-bd6e-439cd3f1cee6
< 1.9.6
MEDIUM 6.4 The Include Mastodon Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'include-ma… wordfence
1ece669f-2e88-4c41-a566-5521424e9c69
< 6.3.6
MEDIUM 6.4 The RumbleTalk Live Group Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
1ec7d4f6-75fa-497b-a639-f7c365c7f195 MEDIUM 6.4 The Aparat Video Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
1ec186b0-72f0-4017-ad24-1c82247a23ec MEDIUM 6.4 The Pinterest RSS Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "prw_shortcode" short… wordfence
1ec0f7d1-a8d0-4dfd-96f5-aee0329bb8ca
< 1.1.4
MEDIUM 6.4 The Bloglo theme for WordPress is vulnerable to Stored Cross-Site Scripting via author names in all versions up to, and … wordfence
1ea4b216-0b29-45eb-bd61-962f76265ba6
< 1.2.2
MEDIUM 6.4 The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions … wordfence
1e99c10d-6632-4520-9239-9b831becd103
< 1.5.4
MEDIUM 6.4 The Vision Interactive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shortcode’ functio… wordfence
← Prev 721 722 723 724 725 726 727 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top