🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 725 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1e9641e2-fe33-4e22-895e-7974b4da6866 MEDIUM 6.4 The Torro Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.… wordfence
1e8abfd1-6e16-4c86-b430-44cec21a5267 MEDIUM 6.4 The Widget Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in ve… wordfence
1e81208c-771f-409e-b665-b07def0ca774 MEDIUM 6.4 The Uji Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘uji_popup_code’ shortcode i… wordfence
1e7f5355-b87b-4720-8998-c081d005827b MEDIUM 6.4 The Certifica WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘evento’ parameter in all… wordfence
1e7efb39-fada-4167-825c-21cc31948a63
< 9.112.4
MEDIUM 6.4 The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_sns… wordfence
1e5e16c9-53d2-4fdd-8370-920b22f52033
< 2.6.3
MEDIUM 6.4 The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image EXIF metadata in versions up… wordfence
1e5cbe1f-0a16-4301-a83c-af9456afe44d
< 1.2.9
MEDIUM 6.4 The WP To Do plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.8 d… wordfence
1e4f0d78-caa0-4575-a090-e1c12d4ed8fd
< 1.3.7
MEDIUM 6.4 The Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More plugin for WordPress is vul… wordfence
1e498dd0-0adc-425f-aae2-67c75c202f48
< 1.6.2
MEDIUM 6.4 The Primary Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
1e340264-7cc0-4598-972f-aaa1fda2096b MEDIUM 6.4 The Image Slider by NextCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
1e257954-9e44-4939-8e01-efceb3c0953a MEDIUM 6.4 The Ninja Beaver Add-ons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl… wordfence
1e1bf208-c188-4dfb-85ff-bf395ed2cbec
< 5.9.9
MEDIUM 6.4 The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.9.8… wordfence
1e0f7686-1c8c-49d6-9d0b-3c8df6c24d0d
< 1.0.13
MEDIUM 6.4 The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordi… wordfence
1e0f35be-fbd1-4063-a1c8-a8e4398d8f0a
< 1.1.0
MEDIUM 6.4 The Bitspecter Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versi… wordfence
1e08ab05-748a-440f-b4ce-b58554cbc9e4
< 4.1.1
MEDIUM 6.4 The Top 10 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.0 due… wordfence
1df421ac-c8fc-4505-989e-1d822ca6de7a
< 2.2.6
MEDIUM 6.4 The WP Social Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in … wordfence
1df1e56e-7a1f-4e89-8df2-bda9dc1ec1dc
< 2.4.19
MEDIUM 6.4 The Post Grid, Post Carousel, & List Category Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… wordfence
1de269b5-7262-45c8-8819-00982f196597 MEDIUM 6.4 The WP show more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's show_more shortcode … wordfence
1dd8a463-a4af-4297-be6b-0192a4534bb5 MEDIUM 6.4 The RainbowNews theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.7… wordfence
1dd0bb5b-2eb5-46f0-8942-2885b1138b70 MEDIUM 6.4 The My Album Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image titles in all versions … wordfence
1dc4acdc-754f-4ee0-947d-ff0c277e8181
< 1.0.1
MEDIUM 6.4 The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions… wordfence
1dc30a32-3b02-4226-8a73-5086949ed92c
< 3.6
MEDIUM 6.4 The Penci Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
1dab93f3-8068-4655-aa3d-a9f4c8dc9d61
< 2.2.0
MEDIUM 6.4 The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in vers… wordfence
1da39f3d-512c-49e0-89cb-672783e5ca4e
< 9.88.2.0
MEDIUM 6.4 The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CTA post func… wordfence
1da28958-fee8-4108-9c7a-6e9b9b5ccc0f MEDIUM 6.4 The Posten plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.0.1 due… wordfence
← Prev 722 723 724 725 726 727 728 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top