πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 730 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
19f3d3a4-1742-4e3f-97c5-acf960c3cdb5
< 1.3.8
MEDIUM 6.4 The Ultimate Form Builder Lite plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includi… wordfence
19cb39d4-f2b4-4f94-8896-ba714567e1ed
< 8.1.11
MEDIUM 6.4 The Quiz And Survey Master plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a question title in ver… wordfence
19c463d1-41fa-4386-b755-a14d1e68c5bd
< 1.3.1
MEDIUM 6.4 The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPres… wordfence
19bf984d-fb2b-4a7e-828c-4f75175b4c1f
< 1.3.1
MEDIUM 6.4 The Universal Analytics plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.3… wordfence
19bdbde1-1414-4113-890e-b6c96b8a6e11
< 2.1.5
MEDIUM 6.4 The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribu… wordfence
19b7cadd-b1b9-4f1d-ab30-78e0b46ad21a
< 3.18.1
MEDIUM 6.4 The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and… wordfence
19aa998d-4a1a-43d7-a600-3320d19ee84f
< 1.1.8
MEDIUM 6.4 The HT Team Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
19a8265b-4a92-41d3-a051-61c60d44bc67 MEDIUM 6.4 The WP MediaTagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin… wordfence
19a672c6-e911-46bb-a55b-c5788eedca3e MEDIUM 6.4 The brodos.net Onlineshop Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Bro… wordfence
19a3fc90-b81c-4451-80e0-cead99a2dcd9 MEDIUM 6.4 The Switch CTA Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wppw_cta_box' shortcode in… wordfence
19a10039-2fe0-4489-86bf-f93c0e18a1a0
< 1.7.5
MEDIUM 6.4 The Custom Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
198b56cd-ac1a-4963-a2db-0a04f6b2fa2c MEDIUM 6.4 The Power Mag theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.5 d… wordfence
1989fe85-5c32-4671-bd20-f9d05cb5034c MEDIUM 6.4 The Portfolio – Filterable Masonry Portfolio Gallery for Professionals plugin for WordPress is vulnerable to Stored Cr… wordfence
1988ff5e-2d3f-4901-8bcc-eb0a7da7566c
< 2.8.5.3
MEDIUM 6.4 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
19743a65-00be-47ec-a2c2-a6bac759b745
< 1.14
MEDIUM 6.4 The Selection Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
19700658-1bef-4e85-a995-d86fff508cdf
< 2.5.9
MEDIUM 6.4 The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
196cbc3f-b794-49e2-8769-b5277c2b8f76
< 1.1.4.9
MEDIUM 6.4 The Ibtana – WordPress Website Builder WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in … wordfence
1954a659-668f-4d09-b6d5-d1dbafb5b030
< 1.2.1
MEDIUM 6.4 The GS Shots for Dribbble plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
1954040c-2188-48b7-9f21-9a0c851c9165
< 2.10.2
MEDIUM 6.4 The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled Fanc… wordfence
19439622-6396-4f10-ab71-aa243b6812fa
< 1.29.3
MEDIUM 6.4 The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-S… wordfence
193d9625-34ab-497f-987e-5a53ca01e73e
< 2.4.7
MEDIUM 6.4 The Music Player for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜album_buy_ur… wordfence
193178a6-d566-4e0a-aa74-8d80a7c8ba04 MEDIUM 6.4 The RecipePress Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Ingredients in all… wordfence
192e303f-3792-4dde-a4a9-30944720cabb
< 2.7.13
MEDIUM 6.4 The Mollie Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7… wordfence
192b5920-5405-49b8-8224-3afb36f3f816
< 1.3.0
MEDIUM 6.4 The Show-Hide / Collapse-Expand plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's short… wordfence
1921dcf9-d23b-4566-a0e5-9e9d5875ef82 MEDIUM 6.4 The Carousel Anything For WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ver… wordfence
← Prev 727 728 729 730 731 732 733 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top