πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 735 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1516280e-796e-4011-b15f-b754860ad414
< 2.1.3
MEDIUM 6.4 The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget tags in… wordfence
1512d911-167f-4653-ab20-cb057b83dab1
< 2.2.86
MEDIUM 6.4 The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
15123d5f-eb24-46e3-81ec-7dd4f108a42d MEDIUM 6.4 The Google Maps v3 Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod… wordfence
150d9d64-6f7f-4646-b03f-dbc63fd0e791
< 3.2.1
MEDIUM 6.4 The Nelio Content – Best Editorial Calendar & Social Media Scheduling plugin for WordPress is vulnerable to Server-Sid… wordfence
14feb451-2ece-467b-abf0-7abac26e40c1
< 6.7.0
MEDIUM 6.4 The Slider Revolution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… wordfence
14ee8268-1371-42c9-9861-e9a11f4fbd95
< 1.5
MEDIUM 6.4 The Quran Phrases About Most People Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers… wordfence
14ee4247-4cfe-440b-add2-d5d840b1f114 MEDIUM 6.4 The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lin… wordfence
14e897f0-11e6-43b1-908c-be4ecdc7fd58
< 3.9.2
MEDIUM 6.4 The WP Ultimate Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpupg-text… wordfence
14dd84e5-69fa-4de9-b72c-dfedfd85582c
< 3.1.4
MEDIUM 6.4 In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) ac… wordfence
14d52936-8fb6-464b-9c0f-038fba0ee57f
< 2.2.1
MEDIUM 6.4 The Enter Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1… wordfence
14c857aa-5c6e-4a1a-b122-efb5d53a56cb MEDIUM 6.4 The Biltorvet Dealer Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
14c07d55-285b-4c7c-bed6-4c5224a7044a MEDIUM 6.4 The Extra Charges To Payment Gateway For WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
14b89618-8a30-4b8c-9490-f05e8fa8ca8a
< 3.2.3
MEDIUM 6.4 The FlatPM – Ad Manager, AdSense and Custom Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
14b45907-2602-40b4-a497-9c1d4823c386 MEDIUM 6.4 The Embed Google Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
14ae2d0f-5c50-4498-8809-e3425d61ed0e MEDIUM 6.4 The MeinTurnierplan.de Widget Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
14ab5d7c-ab46-4a53-b0d2-8b331e204cf3 MEDIUM 6.4 The Slider comparison image before and after plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p… wordfence
14a20f9c-cf5a-4d57-b723-ad29a12c8881
< 1.1.0
MEDIUM 6.4 The Easy Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜esrcpt_slider_al… wordfence
149edbdf-4a27-4d79-8dd1-b5b3efbf648b
< 2.4.0
MEDIUM 6.4 The Ticketmeo – Sell Tickets – Event Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
149e60cc-9612-4651-b02d-4b68a3533d36
< 1.3.2
MEDIUM 6.4 The Mailgun Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mailgun_su… wordfence
147bada2-036d-4e35-9ba2-59ad382afeb9
< 1.3.7
MEDIUM 6.4 The Plexx Elementor Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
1473bb66-8586-4174-b6ce-32502ad7a9c7
< 4.16.4
MEDIUM 6.4 The Real 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
145c0ecc-3af1-4e31-b7e3-329564fb0a21 MEDIUM 6.4 The Extender All In One For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
1453815d-4e28-41ec-9aa4-4fd2899c619a
< 3.10.1
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AGe Ga… wordfence
1451e291-f25a-4402-a613-c94330e4bf05
< 1.4.2
MEDIUM 6.4 The Ajax Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
144efb5e-ef90-433c-9122-dfcfebb10921 MEDIUM 6.4 The Mosaic Gallery – Advanced Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
← Prev 732 733 734 735 736 737 738 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top