πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 731 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
19202eb5-9a04-4484-8ca2-746610c31fe6
< 2.4.2
MEDIUM 6.4 The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
1917eabd-0ba2-4878-87ea-8c0c9c00b6f5
< 2.1.7
MEDIUM 6.4 The Shortcode For Current Date plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its attribu… wordfence
191759f5-8801-4483-933c-77811b63eb4f
< 1.5.4
MEDIUM 6.4 The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to unauthorized access due to a mi… wordfence
1903527e-d7d9-48a0-b59d-65ec5e14def2
< 7.9.1
MEDIUM 6.4 The Element Pack - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-… wordfence
18e2a443-381c-46cd-85c7-20716f4e59c1
< 1.5.0
MEDIUM 6.4 The ShMapper by Teplitsa plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shmMap' sho… wordfence
18d1feee-347c-4f43-a01b-67b3d0a5b2d6 MEDIUM 6.4 The Product Customizer Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in a… wordfence
18a58071-b394-4dc0-9759-6373a5f22f47
< 1.2.5
MEDIUM 6.4 The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
18a20bd4-a172-40b5-9ff3-77e593cff4f5 MEDIUM 6.4 The Education LMS theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.0… wordfence
189090a0-26fd-4a0e-b663-24d28266b56b
< 2.7.1
MEDIUM 6.4 The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
188f00f8-82f2-4166-9d6e-af996fe66422 MEDIUM 6.4 The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
188498ae-e985-470f-9c71-666875ceb333 MEDIUM 6.4 The IG Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.… wordfence
187d4d8d-d1e1-4171-b54d-38455cc659b8 MEDIUM 6.4 The nK Themes Helper plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includ… wordfence
185d380e-7e23-4260-bdeb-e88c8625f690 MEDIUM 6.4 The Korea SNS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.0 … wordfence
18531eed-3150-424c-970c-5975afe7546a MEDIUM 6.4 The Display Custom Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) … wordfence
18510b77-1c73-4f19-88e6-572936132d73
< 1.7.7
MEDIUM 6.4 The Blog Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.… wordfence
1822fd58-0dba-4b15-9702-32e3aa4405b3
< 3.0.5
MEDIUM 6.4 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blog post rea… wordfence
181e6f3a-dbcf-44a6-b725-6325d9e56453
< 3.6.6
MEDIUM 6.4 The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all vers… wordfence
181ad412-2c16-4866-b477-7ce65996adb9
< 5.2.5
MEDIUM 6.4 The Feedzy plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 5.2.4. Th… wordfence
17f12e75-0bb6-48ed-9ba2-17caab268d61
< 2.7.7
MEDIUM 6.4 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
17f118c5-c485-448b-8ab7-3f7fd44be583 MEDIUM 6.4 The WP Responsive Testimonials Slider And Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
17f0dc1b-af69-4bcc-9714-f6432cfca668 MEDIUM 6.4 The WP Custom Post Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
17ecebfd-b07f-415f-892f-e069ab84031a
< 3.4.0
MEDIUM 6.4 The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cro… wordfence
17e853b2-c7ab-478c-9c89-d8e3a42d1a42
< 7.2.3
MEDIUM 6.4 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
17e6537a-37b6-4f13-8bf0-e47e54062979
< 2.1
MEDIUM 6.4 The Animated Typed JS Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
17dbfb82-e380-464a-bfaf-2d0f6bf07f25
< 1.4.9
MEDIUM 6.4 The Podcast Subscribe Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'podcast_subscribe' … wordfence
← Prev 728 729 730 731 732 733 734 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top