ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 737 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
133057a1-4cd5-4e46-9407-d01d80859991 MEDIUM 6.4 The HeartThis plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.1.0 … wordfence
131d07ad-4e87-4137-a5df-2b74db1e9ae8 MEDIUM 6.4 The Fancy Image Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `fancy-img-show`… wordfence
1313c714-d4d4-4ec8-bae8-99af0cee2f43 MEDIUM 6.4 The Contact Form Check Tester WordPress plugin through 1.0.2 settings are visible to all registered users in the dashboa… wordfence
1312ad63-02ed-414d-b807-1a0666da7cf1
< 3.6.1
MEDIUM 6.4 The Typebot plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.0 du… wordfence
130fbb1c-3fc8-4eb0-8f29-6632e413f24c MEDIUM 6.4 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
130f34d8-462a-4812-8526-67beb9ad5efb
< 260101
MEDIUM 6.4 The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plug… wordfence
130ca8ea-74ac-4e0e-ada1-1694d0de7b94 MEDIUM 6.4 The Peekaboo plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1 due… wordfence
130b069d-d224-44af-b2b4-26be7e081f6b
< 2.4.9
MEDIUM 6.4 The Slide Anything plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
12fb237d-348c-4b3d-bc8e-21ab85ec49b4 MEDIUM 6.4 The Timeline Event History plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
12f73a24-3301-499f-8e49-87b151f87f66 MEDIUM 6.4 The The Holiday Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
12ddef9e-6aa3-4b0b-bbee-6ac985f6865a
< 2.7.7
MEDIUM 6.4 The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
12d29542-2b7a-428f-9733-c51bfde18b87 MEDIUM 6.4 The Bootstrap Modals plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
12cfebb8-ae89-410b-a492-340f1553e83e
< 1.1.4
MEDIUM 6.4 The Absolute Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Name' field of a custom … wordfence
12ce97ba-8053-481f-bcd7-05d5e8292adb
< 4.10.1
MEDIUM 6.4 The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' para… wordfence
12c5f64d-1c17-4900-8372-daff5f31e645 MEDIUM 6.4 The WPAvatar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.3 d… wordfence
12b14418-28f0-4786-b8f8-a637fe007b6c MEDIUM 6.4 The WP Recipe Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Skill Level' input fiel… wordfence
12ad3c6c-9a01-4801-b754-79e6e1b2d2a3
< 1.8.7
MEDIUM 6.4 The WooCommerce Product Carousel, Slider & Grid Ultimate plugin for WordPress, versions up to and including 1.8.6, is vu… wordfence
12a89b8f-554c-4d92-adb2-ec84138d568d MEDIUM 6.4 The Post Rating and Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ paramet… wordfence
12a750c6-85b6-48fc-b006-adf0121610dc
< 2.6.1
MEDIUM 6.4 The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in … wordfence
12a1085e-fd28-4f3a-a0e0-9de15a42756d MEDIUM 6.4 The WordPress Image shrinker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an… wordfence
129cc3b0-4f48-4846-902e-be5cd339f537
< 5.6.4
MEDIUM 6.4 The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
1295f1a0-1f5a-4707-96cc-c408a6819e87
< 2.17.3
MEDIUM 6.4 The Elegant Themes Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
129343bc-c049-4ced-9451-e6083558c814 MEDIUM 6.4 The Query Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.3.… wordfence
128d3046-94a0-465c-9225-a3ce652f5282
< 4.3000000023
MEDIUM 6.4 The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
12777db6-125e-42dc-b4b5-694826ec3579 MEDIUM 6.4 The Pinterest Pinboard Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
← Prev 734 735 736 737 738 739 740 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top