πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 733 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
16d8eab2-953a-46bf-a0f6-296bcea86305
< 3.3.1
MEDIUM 6.4 The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… wordfence
16d4ff25-3dae-437f-b6a5-703a3b879904 MEDIUM 6.4 The Gallery: Hybrid – Advanced Visual Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ver… wordfence
16d083bc-d726-4291-bc6d-a7bf83fa78c3
< 1.7.1057
MEDIUM 6.4 The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed … wordfence
16cd88cc-b459-43a9-ae0e-08c01957a111 MEDIUM 6.4 The UltraAddons Elementor Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
16c6fec8-81ec-477a-9942-10fd3adb8fa4
< 1.0.7
MEDIUM 6.4 The Docus – YouTube Video Playlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'docuspla… wordfence
16bbabe5-e8cf-43fa-ae7d-326045464192
< 28.1.2.2
MEDIUM 6.4 The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Ser… wordfence
16b37992-a87e-42bb-ab0f-cb32506874e9
< 3.4
MEDIUM 6.4 The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versi… wordfence
16b0947e-3bb2-4150-b810-2e77de3e75da MEDIUM 6.4 The WHA Crossword plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
16af8724-595c-4daa-80bd-8125a32cc502
< 25.2.1
MEDIUM 6.4 The Clever Fox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's info box block in all … wordfence
16ac3161-c539-4cc2-9535-d4a21690a7da
< 1.9.9.1
MEDIUM 6.4 The Tamara Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
169cb1b8-8a37-4a8b-b824-c31ef132b88a
< 5.6.8
MEDIUM 6.4 The bbp style pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'display-top-users… wordfence
169a857f-1ae0-40f6-8a34-10c573af59c5
< 2.7.0
MEDIUM 6.4 The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is … wordfence
1698c93e-7ed1-4914-80d5-7e198a5360bf
< 2.3
MEDIUM 6.4 The Job Manager by JobScore plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and… wordfence
1688e2d5-ef79-434f-82ca-7630c5c9343c
< 51.1.63
MEDIUM 6.4 The King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Build… wordfence
1682d8d5-665d-4ed8-825c-556e3d3184e3 MEDIUM 6.4 The Processing Projects plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
16805921-3c4c-43ce-b1e2-7c91da8f0a7e
< 2.6.1
MEDIUM 6.4 The GetResponse Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
167dedfa-36cc-4b01-8ea4-8eda8742953c
< 4.1.4
MEDIUM 6.4 The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps… wordfence
167d3e1d-be74-4bfb-b3bf-e2c53d90e12f
< 6.0.8
MEDIUM 6.4 The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
1671405d-27db-4485-87c0-c6405c93f6ad MEDIUM 6.4 The PDF.js Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
166c56b4-bf94-4b95-9efe-16219d85f273
< 4.40
MEDIUM 6.4 The (Simply) Guest Author Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
165f988d-ec6d-44f7-8884-23aedc2fcb08
< 1.0.8
MEDIUM 6.4 The Text Prompter – Unlimited chatgpt text prompts for openai tasks plugin for WordPress is vulnerable to Stored Cross… wordfence
165bafd4-0cef-4936-af21-6a8ffcfccaef MEDIUM 6.4 The PIXNET Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtm' and 'venue' parameters… wordfence
165406fe-c6a5-4d2b-aad9-a860957a446e
< 5.0.1
MEDIUM 6.4 The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
1653e5a9-d2bb-42e3-be0d-27356fbde2ce MEDIUM 6.4 The Post Flagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'flag' shortcode in … wordfence
1643fe92-961c-40de-93c1-78cfeb09506d MEDIUM 6.4 The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gplusnamelink' shortcod… wordfence
← Prev 730 731 732 733 734 735 736 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top