πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 729 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1abee6b1-618b-491c-8017-d74e43c6aa47
< 1.5.1
MEDIUM 6.4 The Waymark plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.0 du… wordfence
1ab05954-9999-43ff-8e3c-a987e2da1956
< 1.4.0
MEDIUM 6.4 The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid wi… wordfence
1aa9d836-4e13-4c6a-b1e6-a8f984805842
< 1.0.2
MEDIUM 6.4 The Your Simple SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in al… wordfence
1aa97f41-1bbd-4ab6-8edd-aef370edfedf
< 1.6.0
MEDIUM 6.4 The WebMan Amplifier plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
1aa50601-5d1a-4d01-9053-5bf7bc4772d7 MEDIUM 6.4 The Easy Modal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.0… wordfence
1a9a254e-f964-49ac-a239-ba9898230b00
< 1.0.7
MEDIUM 6.4 The Gutensee plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0… wordfence
1a93ff8a-364f-4ec4-9c32-208c7a3e1fc1
< 0.95.0
MEDIUM 6.4 The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' sho… wordfence
1a8f71ab-e787-44ba-b159-08f66df8a5fd
< 1.7
MEDIUM 6.4 The Penci Podcast plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
1a8ca426-34cd-4c98-ae24-f3f31a7fcae5 MEDIUM 6.4 The Mortgage Calculator / Loan Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
1a849338-8dd9-49d2-ab7c-29d4b729877b
< 1.3.4
MEDIUM 6.4 The Hash Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
1a7dbb82-b484-4b86-b8dc-7a1e7291dec2
< 1.28.2
MEDIUM 6.4 The Express Payment For Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribut… wordfence
1a7bb274-9bbf-4d78-ad81-0e7ac6b7b265
< 4.7
MEDIUM 6.4 The Smart Agenda – Prise de rendez-vous en ligne plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
1a766b5b-e21e-4009-86d9-7f0a5c91ed51 MEDIUM 6.4 The Easy SVG Allow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded SVG file in all ver… wordfence
1a76571a-f820-4902-afa9-287b59a11d14
< 3.0.8
MEDIUM 6.4 The Nested Pages plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in version… wordfence
1a73c078-ce66-4131-8bd7-6fd48fc9fa84
< 3.33.4
MEDIUM 6.4 The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Text Path widget in all… wordfence
1a684ca7-0856-418e-9229-3e74dafb5c89
< 3.4
MEDIUM 6.4 The WP Database Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versi… wordfence
1a576033-d3f5-48cf-b0b9-b11ea388a6d9
< 1.5.43
MEDIUM 6.4 The Page Builder: Live Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
1a3fe49b-cc0d-4b29-aae5-46307483b8d4
< 3.21.1
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up… wordfence
1a3ebfba-7523-48a4-a315-4395be2cebef
< 1.1.31
MEDIUM 6.4 The Heateor Social Login WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sh… wordfence
1a3137a1-8e46-44c6-8edd-ad9fc4d66e0b
< 5.4.11
MEDIUM 6.4 The Fuse Social Floating Sidebar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file upload f… wordfence
1a2b0ff4-9471-4fd0-ac1a-ed5b7b4af4ff
< 1.0.36
MEDIUM 6.4 The NewsMunch theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versi… wordfence
1a2acbf7-ec3f-44d7-b166-ad0745a2e9ad
< 2.2.3
MEDIUM 6.4 The Dadevarzan WordPress Common plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
1a10cc0e-3b74-4a18-9ef8-7370a45d64ef
< 2.2.8
MEDIUM 6.4 The JetTabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.7 du… wordfence
1a0e93cb-4311-4b38-8eb4-17152e1f3475 MEDIUM 6.4 The Vertical scroll recent post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortc… wordfence
1a09dcc4-37ee-425d-b824-a593c22d711f
< 1.8
MEDIUM 6.4 The Auto iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all version… wordfence
← Prev 726 727 728 729 730 731 732 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top