πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 736 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
144d755a-e61a-4ecd-9d9a-9c6e3a1e6ea2
< 5.10.2
MEDIUM 6.4 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… wordfence
143c5f1f-032c-4207-9401-20f18efcad9d
< 4.5.1
MEDIUM 6.4 The Employee Directory – Staff Listing & Team Directory Plugin for WordPress plugin for WordPress is vulnerable to Sto… wordfence
1427ab4f-be7c-4c5c-92a5-aa486c113ba9
< 2.2.0
MEDIUM 6.4 The JetWooBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
141e5e08-efc3-4da7-ada3-4774dac88884
< 5.7.3
MEDIUM 6.4 The Podlove Web Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' variable in versi… wordfence
14043276-ba0a-4862-a1a7-00b4c372c5bc
< 1.39.3
MEDIUM 6.4 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored C… wordfence
13ffe550-699a-4244-b0e1-859c113d77c0
< 2.2.3
MEDIUM 6.4 The Stock History & Reports Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… wordfence
13eed921-d4da-4729-a02f-c9485f7b3266 MEDIUM 6.4 The LeadBI Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
13e939ed-8c4f-43f0-b19b-3f6a48242cb4
< 2.7.1
MEDIUM 6.4 The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to… wordfence
13d2a333-1f45-457e-a48b-38c1e0793eeb
< 1.1.2
MEDIUM 6.4 The OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable … wordfence
13cde31e-8b20-42a2-ad5b-b5154c90f765 MEDIUM 6.4 The Assist24 Help Desk plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
13c22ad6-eecb-4f05-9dce-76a721b4744c
< 2.0.35
MEDIUM 6.4 In the Best Image Gallery & Responsive Photo Gallery – FooGallery WordPress plugin before 2.0.35, the Custom CSS field… wordfence
13bdd763-8785-4441-8798-5bcc906cb9b4 MEDIUM 6.4 The Embed Google Photos Album Easily plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
139b081d-17b1-4e1f-9d22-cf3f9de123f5 MEDIUM 6.4 The Add Posts to Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [add_posts_fun… wordfence
139ac1ad-d04d-48fc-85a4-6d07cd2e824a MEDIUM 6.4 The ICS Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.6 d… wordfence
139a264b-082b-45db-ac9e-4974bf86c56f
< 3.0.3
MEDIUM 6.4 The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulne… wordfence
139009b5-69d4-44ca-820c-766645828e5e
< 2.0.1
MEDIUM 6.4 The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'child_pages' shortcode in … wordfence
1384c53a-9c6f-4372-98e4-14c9ba213968 MEDIUM 6.4 The Caxton – Create Pro page layouts in Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
137e97be-6d70-44c8-8b28-7e110d85768e MEDIUM 6.4 The Wezido plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2 due t… wordfence
13753c4d-1b51-4db2-a69e-523857a50e55 MEDIUM 6.4 The WP Dispensary plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpd_menu' shortcod… wordfence
13703cee-a277-4f8a-ad45-53c82118682b
< 3.2.39
MEDIUM 6.4 The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-… wordfence
13617b70-9b57-4873-9942-12bffed411e2
< 6.5.0
MEDIUM 6.4 The WooCommerce Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
135783c5-8175-4775-a013-f1e2bef04479 MEDIUM 6.4 The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` shortcode `readmorete… wordfence
1351cd6b-ae22-4363-b36b-f892c504f5d9
< 3.7.13
MEDIUM 6.4 The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct s… wordfence
13517c2f-43ce-4e9a-81c4-d422b0e7273a
< 2.8.3.7
MEDIUM 6.4 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
13436238-f14a-445b-9a9b-fbcf23b7b498
< 1.8.24
MEDIUM 6.4 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
← Prev 733 734 735 736 737 738 739 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top