πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 734 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
163ec640-13bc-40da-88e2-4c8c079a247b
< 5.9
MEDIUM 6.4 The Page-list plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.8 du… wordfence
16320b5e-1cb5-4e6d-ad2e-8ccd9cfa45ef MEDIUM 6.4 The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
1627e235-7836-43dc-a3f6-7f79da6ab229
< 3.5.3
MEDIUM 6.4 The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
162595bb-d41b-4dfd-bfda-3a1e5794eaaf
< 3.06
MEDIUM 6.4 The Simple Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versio… wordfence
1623c6a1-e4dd-4c23-b00b-26b19a319038
< 3.3.0
MEDIUM 6.4 The MyOrderDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.… wordfence
1621937e-1f4c-4031-a4dd-f7b22c2af1b9 MEDIUM 6.4 The WP Smart Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includ… wordfence
1610b3dd-582e-4ff2-956a-95845361c66b
< 1.0.0
MEDIUM 6.4 The Dyslexiefont Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versio… wordfence
1603c61b-11a3-41e5-b339-a9411b02f383
< 2.2.2
MEDIUM 6.4 The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget… wordfence
15fb0a26-e415-4ccb-b83d-d8f7b36bce66
< 4.3.4
MEDIUM 6.4 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skin'… wordfence
15edf742-61e4-4b4f-915d-99e6b3332f5f
< 1.1.32
MEDIUM 6.4 The Heateor Social Login WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up … wordfence
15ed3837-2a52-4d1d-81da-a704aceac684
< 4.9.12.1
MEDIUM 6.4 The Virtue/Ascend/Pinnacle Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
15e8c123-15e9-448b-b4eb-979b70d87f50
< 1.0.6
MEDIUM 6.4 The Sastra Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
15e2efa7-3e29-4ea7-a781-3290725fcc76
< 3.54.6
MEDIUM 6.4 The WordLift plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.54.5 … wordfence
15d66a77-d650-4209-9ad4-b2e157cd123a
< 1.12.1
MEDIUM 6.4 The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, a… wordfence
15d61530-5ef9-4dce-8ace-6d8cc07c7b5e MEDIUM 6.4 The WP Category Post List Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in vers… wordfence
15d36bb4-788a-4491-954c-74814866e07a
< 2.9.30
MEDIUM 6.4 The MicroPayments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
15c1d7e1-e510-4cba-8da1-79e18b2eed22
< 1.6.23
MEDIUM 6.4 The ReviewX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.22 d… wordfence
15b60d5e-fedc-4428-9546-cbb26b99572e MEDIUM 6.4 The CodeBard Help Desk plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… wordfence
15aabe3b-1b77-4e4e-9710-cf06924dbcbf
< 1.6.6
MEDIUM 6.4 The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up … wordfence
15947764-a070-4715-bd44-cb79b62ed59d MEDIUM 6.4 The Font Awesome More Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' shortcode in ve… wordfence
1592108b-acc0-47da-bbff-3202cbc345e7 MEDIUM 6.4 The WP NG Weather plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ng-weather' shortc… wordfence
157eddd4-67f0-4a07-b3ab-11dbfb9f12aa
< 2.8
MEDIUM 6.4 The HTML filter and csv-file search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '… wordfence
157a02dc-542e-4b2b-a847-9abccccda20c
< 3.3.0
MEDIUM 6.4 The Save as PDF Plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up … wordfence
15754167-77f5-4a23-982f-8356f9925358
< 5.9.0
MEDIUM 6.4 The Divi plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.8.1. This… wordfence
151b0aa9-c5c9-48ab-8b73-22ee42666824
< 1.6.3
MEDIUM 6.4 The YOGO Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yogo-calendar' shor… wordfence
← Prev 731 732 733 734 735 736 737 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top