πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 738 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
12772ebe-b146-4cff-bc95-3ec7045f15ab
< 2024.04.09
MEDIUM 6.4 The Website Content in Page or Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's s… wordfence
1266c6df-214b-4b6b-8f1d-a67385469bf5
< 4.10.2
MEDIUM 6.4 The oik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes such as bw_contact… wordfence
12660e7a-51fc-42c5-8a09-49df1db51efb MEDIUM 6.4 The Better RSS Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
1257da54-e008-4e25-bc83-36246f00960e
< 2.2.5
MEDIUM 6.4 The WP Upload Restriction plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saveCustomType' fun… wordfence
12515236-753e-49e8-b8c8-b0c8831c6005 MEDIUM 6.4 The Relogo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,… wordfence
124bf96a-9ace-428a-897b-24243d5cb260
< 1.2.3
MEDIUM 6.4 The Smart Auto Upload Images – Import External Images plugin for WordPress is vulnerable to Server-Side Request Forger… wordfence
12443e0c-2a03-4f62-bf89-cf0497f44a26
< 4.2
MEDIUM 6.4 The Content Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid and List widge… wordfence
123d6216-3174-40c9-bdb9-405e5a5ca129
< 1.0.9
MEDIUM 6.4 The Print Page block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
122a08f7-4e82-494a-b1a9-00ae3d9465ff
< 1.1.0
MEDIUM 6.4 The Moose Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
1227f3bc-0bb3-4b80-ad69-2d4314fafbe4
< 1.26
MEDIUM 6.4 The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aThemes Slider but… wordfence
120c9d81-0dff-4b70-b565-fedda2c089e8
< 5.6
MEDIUM 6.4 The XStore Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.6 due to insuffici… wordfence
120ba9e5-9594-4a4f-b475-ef3fcf5f4565 MEDIUM 6.4 The Pollcaster Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in… wordfence
120566a0-7e10-4a07-9de9-98e11d8145b1
< 3.20.10
MEDIUM 6.4 The Markup Markdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via markdown links in all versions… wordfence
11ffb8a1-55d2-44c5-bcd2-ba866b94e8bc
< 5.3.2
MEDIUM 6.4 The Auto Amazon Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in versi… wordfence
11fb823c-c3d3-456d-b606-b01a8307c25a MEDIUM 6.4 The Simple Image Popup Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sip… wordfence
11f01584-e389-4551-b151-f3f0686d1d5d
< 3.2.1
MEDIUM 6.4 The Portfolio for Elementor & Image Gallery | PowerFolio plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
11deeb2a-db8c-4380-a541-0c78781f78c6
< 5.9.2
MEDIUM 6.4 The WP Travel Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
11dceac7-7ff8-4384-9046-919c38947c32
< 13.4
MEDIUM 6.4 The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
11dbc647-fa96-4c63-8f13-0c8ea6f33919
< 1.91.2
MEDIUM 6.4 The WP-PostRatings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Google rich text snippets in ve… wordfence
11d68c98-3d7e-42af-be61-6bb5428b73b6
< 2.3.1
MEDIUM 6.4 The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stor… wordfence
11d4c028-94c1-4b78-92f8-0f3303725651
< 3.19.0
MEDIUM 6.4 The Flatsome theme for WordPress is vulnerable to Stored Cross-Site Scripting via the UX Countdown, Video Button, UX Vid… wordfence
11ad51d9-d0b6-4a47-875c-d7a6727f4d7c
< 2.9.4.4
MEDIUM 6.4 The myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.4.3 d… wordfence
11aac185-191b-4f7b-8472-84d3decd582f
< 2.3.1
MEDIUM 6.4 The Perfect Font Awesome Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's … wordfence
11a7e69d-4bb3-4a7f-89c8-c705987aeb5d MEDIUM 6.4 The Inline Click To Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
1196b20e-5fa4-44bf-8cdc-35e1c0db0c74
< 5.4.5
MEDIUM 6.4 The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
← Prev 735 736 737 738 739 740 741 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top