πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 732 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
17c1de7b-5178-4fbe-a515-169de4323ae7
< 3.11.9
MEDIUM 6.4 The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
17a0d8b3-e54d-4af4-8915-e8b192cc138b
< 1.2.1
MEDIUM 6.4 The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easywavefor… wordfence
17988a66-5b48-4f57-96f8-74e539bc875e
< 1.5.0
MEDIUM 6.4 The File Upload Types by WPForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads … wordfence
1794ef89-3949-44b4-9d42-80cd827ef730 MEDIUM 6.4 The Ruven Themes: Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ruven_b… wordfence
1793922f-c03a-4b66-a2e0-5729f0d4c4d2
< 3.5.8.3
MEDIUM 6.4 The Free Downloads WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
1780e19e-5836-4601-a2e8-a758b245f14f MEDIUM 6.4 The Marmoset Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
177ffbef-b029-4f41-a2f7-a848b5275cc2
< 1.1.5
MEDIUM 6.4 The Jannah - Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
17798563-851b-4f31-aa38-919ec629da94 MEDIUM 6.4 The Botnet Attack Blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
176798cc-9f5f-4524-9172-8f0497e4fc11
< 1.9.4
MEDIUM 6.4 Multiple cross-site scripting (XSS) vulnerabilities in the (1) callback_multicheck, (2) callback_radio, and (3) callback… wordfence
1760fe6e-8153-4479-ae32-2e2f0fa54e12 MEDIUM 6.4 The Ayo Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' parameter of the ay… wordfence
17508063-3cd7-4b61-b7be-23a71b75f6a2
< 2.5.4
MEDIUM 6.4 The Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder plugin for WordPress is vulnerable to DOM-Based Cr… wordfence
174e2bf3-2531-4a53-ade6-3df7e976ed29
< 3.0.9
MEDIUM 6.4 The MasterStudy LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
17457ff2-917d-4cc4-8c5e-c80cd320cc90 MEDIUM 6.4 The SEO Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to, and i… wordfence
173c8c8a-a015-4522-b957-1805f520a77d MEDIUM 6.4 The WooCommerce Menu Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, … wordfence
173c20d5-05aa-4f19-9bbe-985585b09de2
< 2.1.1
MEDIUM 6.4 The Ledenbeheer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.… wordfence
173adc9e-64e6-40da-9ef1-31e35cb179b2 MEDIUM 6.4 The IA Map Analytics Basic plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
173305ee-9c89-4192-8ccf-227947b142d1 MEDIUM 6.4 The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bootstrap_tab' shortcod… wordfence
17301be2-f2bc-4b59-b0ab-65591ffcfa3e
< 2.0.9
MEDIUM 6.4 The Listeo theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `soundcloud` shortcode in v… wordfence
172d8ffc-7ed3-43a6-942c-93b476a4fb50
< 1.0.4.2
MEDIUM 6.4 The OneClick Chat to Order plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes… wordfence
172b6b54-d1de-48f9-ad2f-00d62d7e91fd
< 2.1.2
MEDIUM 6.4 The My IDX Home Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-idx-… wordfence
17240221-01b2-4a21-9e9f-f940280c0fb7
< 3.2.0
MEDIUM 6.4 The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple widgets in a… wordfence
1716743f-8259-40fb-bc9b-53e3dfef8816
< 0.10
MEDIUM 6.4 The WP BookWidgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bw_link' shortcod… wordfence
170a4cf2-d379-4c4e-b9e5-fb3b3bd91a40
< 1.49.1
MEDIUM 6.4 The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress … wordfence
1703a5be-f399-4ea5-8d98-a2efda674aa6
< 3.4.8
MEDIUM 6.4 The Unify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin for WordPress's unify_checkou… wordfence
16e7adef-68ab-4dd6-bd80-252622cfe705
< 3.20.4
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom… wordfence
← Prev 729 730 731 732 733 734 735 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top